Whatever their play, detect and drop the redirects. Good job on noticing it early on!
Ask HN: Why buy domains and 301 redirect them to me?
11–20 of 135 posts
Re: Ask HN: Why buy domains and 301 redirect them to me?
#12People do this for SEO purposes. They think that this increases the amount of backlinks to their site, thus increasing their rank in Google and other search engines. This is less true than it used to be, but people still do it.
Sure, but it's not their site, it's mine! And they're not obvious mouse slips like redirecting googl.com -> google.com - they're more of the form mydomain.com. I was mostly interested in what the actual play from them here is tbh
Re: Ask HN: Why buy domains and 301 redirect them to me?
#13I'm guessing it will look normal but it could provide some insights if something weird is there.
Re: Ask HN: Why buy domains and 301 redirect them to me?
#14Re: Ask HN: Why buy domains and 301 redirect them to me?
#15I think this was a common attack vector around then, but is no longer common.
Re: Ask HN: Why buy domains and 301 redirect them to me?
#16Re: Ask HN: Why buy domains and 301 redirect them to me?
#17Earlier quoted context omitted.
Sure, but it's not their site, it's mine! And they're not obvious mouse slips like redirecting googl.com -> google.com - they're more of the form mydomain.com. I was mostly interested in what the actual play from them here is tbh
Maybe they’ll try to build up traffic to your site from those domains and then push to sell them to you/extort by removing the redirects?
Re: Ask HN: Why buy domains and 301 redirect them to me?
#18Re: Ask HN: Why buy domains and 301 redirect them to me?
#19It’s possible `/` redirects but other hidden routes phish. If someone gets e.g.: a fake password reset email, it might help the attacker bypass sanity checks users make.
If I target a specific region with a phishing link and redirect if the requestor is not in that region I can probably maintain my phishing domains for longer.
Re: Ask HN: Why buy domains and 301 redirect them to me?
#20mostly for phishing (if you're successful), to send e-mail looking like from you
Of all the answers presented so far, this one feels the most plausible to me.