Tuesday, April 25, 2017

Have you been (IDN) homographed


Check this out?

1. Open  the "proof of concept" link in the following article
https://www.xudongz.com/blog/2017/idn-phishing/

2. It will show "apple"

3.  Copy the URL and paste it in a text browser and it will show
https://www.xn--80ak6aa92e.com/

That's IDN Homograph attack

There is NO-WAY you can visually identify if the URL is FAKE.  So, what can you do?
The article above also provides a few hints on how to protect.

Wikipedia Link :
https://en.wikipedia.org/wiki/IDN_homograph_attack


Have Fun

No comments:

Post a Comment