Domain Shadowing
Embed This Widget
Add the script tag and a data attribute to embed this widget.
Embed via iframe for maximum compatibility.
<iframe src="https://tldfyi.com/iframe/glossary/domain-shadowing/" width="420" height="400" frameborder="0" style="border:0;border-radius:10px;max-width:100%" loading="lazy"></iframe>
Paste this URL in WordPress, Medium, or any oEmbed-compatible platform.
https://tldfyi.com/glossary/domain-shadowing/
Add a dynamic SVG badge to your README or docs.
[](https://tldfyi.com/glossary/domain-shadowing/)
Use the native HTML custom element.
Domain Shadowing คือเทคนิคการโจมตีที่ผู้ก่อภัยคุกคามเข้าถึงบัญชีนายทะเบียน [[dns|DNS]] ของโดเมนที่ถูกกฎหมายโดยไม่ได้รับอนุญาต และสร้าง subdomain ที่เป็นอันตรายอย่างเงียบๆ ภายใต้โดเมนที่น่าเชื่อถือนั้น โดยไม่รบกวนเว็บไซต์หลัก เนื่องจากโดเมนหลักมีชื่อเสียงที่ได้รับการยืนยันแล้ว subdomain ที่ถูกซ่อนจึงรับคะแนนความน่าเชื่อถือนั้นมาด้วย จึงไม่น่าถูกบล็อกโดยตัวกรองความปลอดภัย การโจมตีมักใช้ [[domain-hijacking|การขโมยข้อมูลประจำตัวบัญชี]] แทนการยึดโดเมนทั้งหมด ทำให้คงอยู่ได้โดยไม่ถูกตรวจจับ subdomain ที่ถูกซ่อนมักถูกใช้เพื่อโฮสต์หน้าฟิชชิ่ง แจกจ่ายมัลแวร์ หรือโครงสร้างพื้นฐาน command-and-control
ตัวอย่าง
Attackers compromise the registrar account of a law firm, create 'payment.lawfirm.com' pointing to a phishing server, and send invoices to clients — the trusted domain name bypasses email filters.