Settings

Theme

Show HN: Have I Been Squatted? — Check if your domain has been typosquatted

haveibeensquatted.com

22 points by juxhindb 2 years ago · 10 comments

Reader

mikecoles 2 years ago

A different solution that runs locally is opensquat.

https://github.com/atenreiro/opensquat

cloths 2 years ago

This is cool and very useful!

It's a bit slow but understandable, so you'd permutate the input domain and then query DNS? Feels resource heavy, any caching mechanism in place? IMHO it'd be good to add some intro/info on the homepage.

Feedback, Make signing more visbile, currently you'd have to click login -> click on sign up

Feedback, I am expecting a paid premium after login but non, WIP?

  • juxhindbOP 2 years ago

    Thank you!

    > so you'd permutate the input domain and then query DNS?

    Correct, we're running on resource-constrained lambdas right now and hoping to have some breathing room to expand on this soon. We want this to be the most accurate, point-in-time analysis of your domain so we want to push for this to run and scale rather than trying to tap into [expensive] data feeds.

    > any caching mechanism in place? IMHO it'd be good to add some intro/info on the homepage.

    Definitely, we had this prior with Cloudfront. As we're running on HTTP/2 stream, we simply cached the response and replayed it at the edge. We recently added signup/signin which complicated this so we've disabled it for the time. We're going to re-include it using Lambda@Edge shortly.

    > Feedback, Make signing more visbile, currently you'd have to click login -> click on sign up

    Noted!

    > Feedback, I am expecting a paid premium after login but non, WIP?

    Right now we're just giving access to more results after signin. We'll include CSV exports, some detailed results for free to help analysts. We're exploring premium features where you pay for recurring alerts about your domain with report history. Happy to hear what you feel are features you'd be happy to have included (and perhaps pay for?).

    • ianmuscat 2 years ago

      Another reason it may feel a little bit slow is because the client is completing an invisible CAPTCHA challenge to curb bots/abuse (we may be able to improve this experience for authenticated users eventually)

juxhindbOP 2 years ago

Hi HN, I invite all of you to try out Have I Been Squatted. Around a year ago we shared an alpha project called Have I Been Squatted, a small free tool for users to generate and understand their domain’s security posture with regards to typosquatting. The original version hug-to-death’ed[1][2] so we decided to rethink the UI and internals to (hopefully) mitigate this.

Happy to get any valuable feedback, stories or questions. You're also all welcome to our Discord[3] if you want to talk about your use-cases or what you found using our tool!

If you're curious about building your own version, you can try out our open-source permutation library, `twistrs`[4].

[1]: https://news.ycombinator.com/item?id=32985139

[2]: https://lobste.rs/s/k719vs/have_i_been_sqautted_free_dns#c_f...

[3]: https://discord.gg/rJeacCbVhy

[4]: https://github.com/haveibeensquatted/twistrs

quickthrower2 2 years ago

Is the logo someone farting?

  • juxhindbOP 2 years ago

    Oh god we can’t unsee it now. Was meant to be someone “squatting”. This comment is getting framed

shaunpud 2 years ago

I've used https://dnstwist.it in the past

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection