Chrome Blocks Crafty URL Phishing Method

chrome-blocks-crafty-url-phishing-method photo 1

Google this week updated its Chrome web browser to defend against a Unicode manipulation technique that phishing scammers could use to trick internet surfers into visiting malicious websites.

By registering a URL made up of characters from non-Latin alphabets, scammers can make it look nearly identical to that of the website it's trying to imitate, as security blogger Xudong Zheng demonstrated this week. Zheng registered the domain name "xn--pple-43d.com," a Unicode formula known as "punycode" that Chrome, Firefox, and other browsers will display as virtually identical to "www.apple.com."

The technique is known as a homograph attack, and using it in website phishing scams has been theoretically possible since 2009, when the Internet Corporation for Assigned Names and Numbers approved the addition of top-level domain names with non-Latin character sets. It languished in relative obscurity until the past few months, when security researchers and bug chasers began discussing it on Reddit and various developer forums.

Related

  • Don't Fall for This Sophisticated Gmail Phishing ScamDon't Fall for This Sophisticated Gmail Phishing Scam

The increased attention caused Google to change the way the Chrome browser displays URLs. Starting with Chrome version 58, URLs containing Cyrillic characters will only be displayed as text if the domain also contains non-Latin characters. If a user attempts to load a website from a domain like ".com" or ".net" with a Cyrillic character in its URL, the browser will block it as a dangerous site.

It's unclear if Microsoft or Firefox maker Mozilla also plan to implement similair fixes, although Zheng noted that it's possible for Firefox users to implement their own blocking by changing their browser's configuration code. To do so, type "about:config" into the address bar and set the "network.IDN_show_punycode" option to "true." Microsoft and Mozilla did not immediately respond to requests for comment.

Other lesser-used browsers, including Apple's Safari, are not affected by the vulnerability, according to Zheng.

Recommended stories

Relax Chrome Blocks Crafty URL Phishing Method stories

More stories