The New Google .zip TLD: Examining Potential Cybersecurity Risks
While specifically refers to a domain that was used in a high-profile cybersecurity demonstration, the most "interesting paper" on this topic is actually a broader study regarding the security risks of the .zip Top-Level Domain (TLD) . Recommended Research Paper
: A technical preprint (available on arXiv) that discusses the collisions between the namespace for filenames and DNS names. stronka.zip
: An Overview of Threats Exploring the Confusion Between Top-Level Domains and File Type Extensions
: An analysis of 17,000 .zip domains that found over 600 active Windows Trojans hosted on these sites as of March 2024. The New Google
: A user who thinks they are downloading a file from a trusted source is instead sent to the stronka.zip website, which can trigger an automatic malware download. Other Noteworthy Studies
: Attackers can use the @ symbol in a URL to trick browsers. For example, a link like https://google.com∕downloads∕@stronka.zip looks like it is pointing to a download on Google's site. : A user who thinks they are downloading
: Browsers actually treat everything before the @ as "user info" and only care about what follows it.