डोमेन शैडोइंग
Embed This Widget
Add the script tag and a data attribute to embed this widget.
Embed via iframe for maximum compatibility.
<iframe src="https://tldfyi.com/iframe/glossary/domain-shadowing/" width="420" height="400" frameborder="0" style="border:0;border-radius:10px;max-width:100%" loading="lazy"></iframe>
Paste this URL in WordPress, Medium, or any oEmbed-compatible platform.
https://tldfyi.com/glossary/domain-shadowing/
Add a dynamic SVG badge to your README or docs.
[](https://tldfyi.com/glossary/domain-shadowing/)
Use the native HTML custom element.
डोमेन शैडोइंग एक हमला तकनीक है जिसमें एक खतरनाक अभिनेता किसी वैध डोमेन के [[dns|DNS]] रजिस्ट्रार खाते तक अनधिकृत पहुंच प्राप्त करता है और मूल साइट को बाधित किए बिना उस विश्वसनीय डोमेन के अंतर्गत चुपके से दुर्भावनापूर्ण सबडोमेन बनाता है। चूंकि मूल डोमेन की स्थापित प्रतिष्ठा होती है, इसलिए शैडो सबडोमेन उसका ट्रस्ट स्कोर प्राप्त कर लेते हैं और सुरक्षा फिल्टर द्वारा ब्लॉक किए जाने की संभावना कम होती है। यह हमला पूर्ण डोमेन अधिग्रहण के बजाय [[domain-hijacking|खाता क्रेडेंशियल चोरी]] का उपयोग करता है, जिससे यह बिना पता चले बना रह सकता है। शैडो सबडोमेन का उपयोग आमतौर पर फिशिंग पेज होस्ट करने, मैलवेयर वितरण, या कमांड-एंड-कंट्रोल इंफ्रास्ट्रक्चर के लिए किया जाता है।
उदाहरण
Attackers compromise the registrar account of a law firm, create 'payment.lawfirm.com' pointing to a phishing server, and send invoices to clients — the trusted domain name bypasses email filters.