IDN homograph attack
Using visually similar characters in domain names to deceive users
Nº Q1626204 ★★
Uncommon · History
IDN homograph attack
Using visually similar characters in domain names to deceive users
An internationalized domain name (IDN) homograph attack (also homoglyph attack) is a method used by malicious parties to deceive computer users about the identity of the remote system they are communicating with. This is achieved by exploiting the fact that many different characters look alike and the user is unlikely to spot a subtle substitution.
Last price
—
Floor price
—
7-day median
—
30-day sales
0
30-day range
—
In circulation
0
Price history
median
low – high
sales
No sales in this period
Show table
| Date | median | Low | High | sales |
|---|
Sales history
- Last sale
- —
- 30-day average
- —
- 30-day low
- —
- 30-day high
- —
- Sales 7d
- 0
- Sales 30d
- 0
No sales yet.
Anonymous sales: no buyer or seller shown. Figures count player-to-player sales only.
From Wikipedia
An internationalized domain name (IDN) homograph attack (also homoglyph attack) is a method used by malicious parties to deceive computer users about the identity of the remote system they are communicating with. This is achieved by exploiting the fact that many different characters look alike and the user is unlikely to spot a subtle substitution. For example, the Cyrillic, Greek and Latin alphabets each have a letter ⟨o⟩ that has the same shape but have different code points. This kind of spoofing attack is also known as script spoofing. Unicode supports numerous scripts (writing systems), and, for a number of reasons, similar-looking characters (such as Greek Ο, Latin O, and Cyrillic О) each has its own code point despite being homoglyphs. Their incorrect or malicious usage is potentially an opportunity for security attacks. Thus, for example, a regular user of exаmple.com (exаmple.com) may be lured to click on it unquestioningly as an apparently familiar link, unaware that the third letter is not the Latin character ⟨a⟩ but rather the Cyrillic character ⟨а⟩ and is thus an entirely different domain from the intended one. The registration of homographic domain names is akin to typosquatting, in that both forms of attacks use a similar-looking name to a more established domain to fool a user. The major difference is that in typosquatting the perpetrator attracts victims by relying on natural transposition errors commonly made when a URL is entered manually, while in homograph spoofing the perpetrator deceives the victims by presenting visually indistinguishable hyperlinks. Indeed, it would be a rare accident for a web user to type, for example, a Cyrillic letter within an otherwise English word, turning, say, "bank" into "bаnk". There are cases in which an abusive registration can use both typosquatting and homograph spoofing; the pairs of l/I, i/j, and...
Text: Wikipédia, CC BY-SA 4.0. · Image: CoolCanuck (CC0) ·