Question How to verify I'm on the website I want to be on?

Skyzoomer

Senior member
Sep 27, 2007
374
12
81
Assume a website's URL is "thecompany.com".
When I go to the sign in page, it shows "auth.thecompany.com/NewUser"

Although the URL that is displayed in the address bar has an "auth." prefix, can I still be assured that I'm on the legitimate website's sign in page?

IOW, as long as there is "thecompany.com" somewhere in the address bar, then can I be assured that I'm really on "thecompany.com" website?
 

lantis3

Senior member
Oct 18, 2023
279
56
61
Copilot's answer: :p

Verifying the legitimacy of a subdomain involves several steps:
  • Check the URL Structure: Ensure the subdomain is part of a recognized and trusted domain. For example, support.microsoft.com is a legitimate subdomain of microsoft.com.
  • Look for HTTPS: Verify that the subdomain uses HTTPS, indicating it has an SSL certificate and secure communication. The URL should start with https://.
  • Domain Age and Registration: Use tools like WHOIS to check the domain’s age and registration details. Older domains are generally more trustworthy1.
  • Domain Reputation Check: Use services like IPVoid to check if the subdomain is listed on any blacklists or has a bad reputation2.
  • Contact Information: Legitimate websites often provide clear contact details, including a physical address and phone number. Check if the subdomain has this information available1.
  • Google Safe Browsing: Use Google’s Safe Browsing Transparency Report to see if the subdomain is flagged for any suspicious activity3.
  • Content and Design: Evaluate the content and design of the subdomain. Legitimate sites usually have professional design and well-written content. Be cautious of sites with poor grammar, spelling errors, or unprofessional design.
 

Skyzoomer

Senior member
Sep 27, 2007
374
12
81
Copilot's answer: :p

Verifying the legitimacy of a subdomain involves several steps:
  • Check the URL Structure: Ensure the subdomain is part of a recognized and trusted domain. For example, support.microsoft.com is a legitimate subdomain of microsoft.com.
  • Look for HTTPS: Verify that the subdomain uses HTTPS, indicating it has an SSL certificate and secure communication. The URL should start with https://.
  • Domain Age and Registration: Use tools like WHOIS to check the domain’s age and registration details. Older domains are generally more trustworthy1.
  • Domain Reputation Check: Use services like IPVoid to check if the subdomain is listed on any blacklists or has a bad reputation2.
  • Contact Information: Legitimate websites often provide clear contact details, including a physical address and phone number. Check if the subdomain has this information available1.
  • Google Safe Browsing: Use Google’s Safe Browsing Transparency Report to see if the subdomain is flagged for any suspicious activity3.
  • Content and Design: Evaluate the content and design of the subdomain. Legitimate sites usually have professional design and well-written content. Be cautious of sites with poor grammar, spelling errors, or unprofessional design.
Appreciate you detailed response. I just want to know if the "auth.thecompany.com/NewUser" assures that the website is the legit website for "thecompany.com". IOW, since there is "thecompany.com" in the URL, that means I'm on their legitimate website.
Thanks.
 

lantis3

Senior member
Oct 18, 2023
279
56
61
As you can see it's not easy to answer.

The problem is thecompany.com and auth.thecompany.com are not necessarily on same ip address or same machine but still legit.
 

lantis3

Senior member
Oct 18, 2023
279
56
61
for anandtech.com and forums.anandtech.com you can query on dnsquery.org and at least found that
forums.anandtech.com ipv4 "A" record is answered by DNS servers (there are 4) listed in whois query results for anandtech.com

Don't know if other members have netter answer.

 

Skyzoomer

Senior member
Sep 27, 2007
374
12
81
for anandtech.com and forums.anandtech.com you can query on dnsquery.org and at least found that
forums.anandtech.com ipv4 "A" record is answered by DNS servers (there are 4) listed in whois query results for anandtech.com

Don't know if other members have netter answer.

I went to dnsquery.org. Lost me as beyond my understanding.
Thanks.
 

BoomerD

No Lifer
Feb 26, 2006
64,082
12,401
136
My admittedly limited understanding is that if the site is***.the company.com, NOT something like ***.the company.whatever.com, you should be OK.
 

Fallen Kell

Diamond Member
Oct 9, 1999
6,094
456
126
It gets even messier than you think. DNS poisoning is real. Even search results from search engines like google can be fooled into pointing to a bogus site for a company. I think there was an article that can out just yesterday about one such thing that only took the "hacker" 30 minutes to get google to update their search results to point to their spoofed site instead of the real one.

These even pass the https:// cert tests, as the sites obtain a valid cert from a "trusted cert authority" (in quotes because there are way too many of them out there, and too many of those will gladly provide a legit cert to a site if they get paid the processing fees).
 

In2Photos

Golden Member
Mar 21, 2007
1,969
2,006
136
It gets even messier than you think. DNS poisoning is real. Even search results from search engines like google can be fooled into pointing to a bogus site for a company. I think there was an article that can out just yesterday about one such thing that only took the "hacker" 30 minutes to get google to update their search results to point to their spoofed site instead of the real one.

These even pass the https:// cert tests, as the sites obtain a valid cert from a "trusted cert authority" (in quotes because there are way too many of them out there, and too many of those will gladly provide a legit cert to a site if they get paid the processing fees).
I recently typed YouTube in the address bar and hit enter without adding .com so chrome performed a search instead of going directly to the site. The first link on Google showed YouTube but the link was not to YouTube. A Google search for a Google owned site on a Google browser would have sent me to some random website with Lord only knows what kind of content.
 

back2fture

Junior Member
Sep 8, 2024
3
0
6
from theory it's a sub directory '/NewUser' for the local domain 'auth.' on the root domain 'thecompany.com' ('https://www.ibm.com/docs/en/aix/7.1?topic=structure-naming-conventions', 'https://www.ibm.com/docs/en/aix/7.3?topic=resolution-naming-conventions'), but verifying on entry level at least needs looking up IP addresses, whois content and certificates of the variants of the naming scheme (?)
higher level spoofing/phishing(/loosely related shadow banning, e.g. demonstrated on twitter|X ~2022) or server related routings are probably difficult to check from one point only

entering a wrong authentication on first try should provide you with an accustomed error message, but can be a delay in a workflow also

checking certificates from command line in Linux, suggested from 'serverfault.com', like that:
'echo | openssl s_client -showcerts -servername gnupg.org -connect gnupg.org:443 2>/dev/null | openssl x509 -inform pem -noout -text'
 
Last edited: