Dynadot

alert CAREFUL... Phishing attempts using IDN's

Spaceship Spaceship
Watch

TestCase

Note: Doesn't play well with others.Top Member
Impact
2,381
I just came across this warning that I found pretty unsettling,

https://www.wordfence.com/blog/2017/04/chrome-firefox-unicode-phishing/
There is a phishing attack that is receiving much attention today in the security community.

As a reminder: A phishing attack is when an attacker sends you an email that contains a link to a malicious website. You click on the link because it appears to be trusted. Merely visiting the website may infect your computer or you may be tricked into signing into the malicious site with credentials from a site you trust. The attacker then has access to your username, password and any other sensitive information they can trick you into providing.

This variant of a phishing attack uses unicode to register domains that look identical to real domains. These fake domains can be used in phishing attacks to fool users into signing into a fake website, thereby handing over their login credentials to an attacker.

This affects the current version of Chrome browser, which is version 57.0.2987 and the current version of Firefox, which is version 52.0.2. This does not affect Internet Explorer or Safari browsers.

(I couldn't decide if this should be posted using "Alert" or a "Warning" in the subject so I just went with alert...)
 
Last edited:
7
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
Luckily that article does contain a fix for the Firefox browser to make it show IDNs as IDNs.
 
0
•••
0
•••
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back