Two characters open up a world of typosquatting opportunities in Chromium browsers
Researchers say two characters available to typosquatters and phisherfolk can trick Chromium browsers into displaying lookalike URLs as genuine web addresses. Wangling a domain name to look an awful lot like that of a popular website is nothing new. We’ve all encountered phishing sites such as macrosoft[.]com and applle[.]com before in our daily struggles against spam. However, as browsers mature, new characters are always being made available for use. This opens up new opportunities for those whose languages contain characters/homoglyphs that aren’t ASCII-compliant, but it also introduces new ways for attackers to abuse display logic quirks in programs like Chrome and Edge. According to Ian Muscat and Leanne Briffa of Have I Been Squatted, there are still characters available to cyber-imposters that can reliably fool web users into trusting URLs that they certainly should not. …
You're reading a preview. The full article is published by The Register on their website.
Read the full story on The Register

