Bhugi inobvumidzwa kunyoresa nzvimbo dzekubiridzira ne Unicode mavara

phishing webhusaiti

Mazuva mashoma apfuura iyo Soluble vaongorori vakaburitsa kuwanikwa kwavo kutsva de nzira nyowani yekunyoresa domains nehemoglyphs ayo anotaridzika semamwe matunhu, asi anotosiyana nekuda kwekuvapo kwevanyori vane imwe dudziro.

Maseru akadai epasirese (IDN) anogona pakutanga kuona hausiyane kubva kunzvimbo dzinozivikanwa dzekambani nenzvimbo dzekushandira, zvichikubvumidza kuti uzvishandise kubiridzira, kusanganisira kugashira zvitupa zveTLS zvakafanira.

Kubudirira kunyoreswa kwenzvimbo idzi kunoratidzika senge iwo akakodzera maseru uye inonyatso kuzivikanwa, uye inoshandiswa kuita kurwisa kweinjiniya kumasangano.

Matt Hamilton, muongorori pa Soluble, akaona kuti zvinokwanisika kunyoresa akawanda maseru generic top-level (gTLD) uchishandisa Unicode Latin IPA yekuwedzera hunhu (senge ɑ uye ɩ), uye zvakare akagona kunyoresa madomeni anotevera.

Iyo yechinyakare kutsiva kuburikidza neinoratidzika yakafanana IDN domain yakagara yakavharirwa mumabhurawuza uye marejista, nekuda kwekurambidzwa kwekusanganisa mavara kubva kune akasiyana maalufabhethi. Semuenzaniso, iyo fake domain domain apple.com ("xn--pple-43d.com") haigone kugadzirwa nekutsiva chiLatin "a" (U + 0061) neCyrillic "a" (U + 0430), kubvira Kusanganisa kugona kwemavara kubva pamaarufabheti akasiyana hakutenderwe.

Muna 2017, nzira yekudzivirira kuchengetedzwa kwakadai yakawanikwa nekushandisa chete mavara eunicode mudomeini, usingashandise mavara echiLatin (semuenzaniso, kushandisa mavara emitauro ane mavara akafanana neLatin).

Iye zvino imwe nzira yekudzivirira yekudzivirira yakawanikwa, zvichibva nekuti mabharandi anovhara iyo kusanganiswa kweLatin uye Unicode, asi kana Unicode mavara akataurwa mudura iri eboka revatambi vechiLatin, kusanganisa kwakadaro kunotenderwa, sezvo mavara ari eerufabheti imwechete.

Dambudziko nderekuti iyo Unicode Latin IPA yekuwedzera ine homoglyphs yakafanana mukupereta kune mamwe mavara echiLatin: chiratidzo "ɑ" chakafanana "a", "ɡ" - "g", "ɩ" - "l".

Iko kugona kunyoresa domains umo chiLatin chakasanganiswa neakaratidzirwa mavara eUunicode akaonekwa pamwe neVerisign registrar (hapana vamwe vanyori vakanyorerwa), uye masadomaini akagadzirwa mumasevhisi eAmazon, Google, Wasabi uye DigitalOther.

Kunyangwe kuferefetwa kwakaitwa chete paVerisign-manejimendi gTLDs, iro dambudziko Izvo hazvina kucherechedzwa nehofori dzenetwork uye kunyangwe paine ziviso dzakatumirwa, mwedzi mitatu gare gare, paminiti yekupedzisira, yakagadziriswa chete kuAmazon neVerisign sezvo ivo vega vakatora dambudziko zvakanyanya.

Hamilton akachengeta chirevo chake pachivande kusvikira Verisign, iyo kambani inotarisira kunyoreswa kwesizinda kune akakwirira epamusoro-chikamu dura ekuwedzera (gTLDs) se .com uye .net, yakagadzirisa dambudziko.

Vatsvaguriri vakatanga zvakare basa repamhepo kuti vaone matunhu avo. kutsvaga dzimwe nzira dzinogona kuitwa nehemoglyphs, kusanganisira kuongororwa kwenzvimbo dzakanyoreswa kare uye zvitupa zveTLS zvine mazita akafanana.

Nezve zvitupa zveHTTPS, mazana matatu enzvimbo ane homoglyphs akasimbiswa kuburikidza neSitifiketi Transparency marekodhi, ayo gumi nemashanu akanyoreswa mukugadzirwa kwezvitupa.

Iwo chaiwo Chrome uye Firefox mabhurawuza anoratidza madoma akafanana mubara rekero mune notation ine chinamato chekutanga "xn--", zvisinei madomeni anoonekwa pasina kutendeuka mumatanho, ayo anogona kushandiswa kuisa zviwanikwa zvakashata kana zvinongedzo mumapeji, pasi pe kufungidzira kwekudzirodha kubva kunzvimbo dzepamutemo.

Semuenzaniso, mune imwe yenzvimbo dzinozivikanwa nehemoglyphs, kupararira kweshanduro yakaipa yeraibhurari yejQuery kwakanyorwa.

Munguva yekuyedza, vaongorori vakashandisa madhora mazana mana vakanyoresa madomaini anotevera naVerisign:

  • amzon.com
  • chsese.com
  • sslesforce.com
  • Wemasai.com
  • ɩppɩe.com
  • ebyy.com
  • Static.com
  • bvvabativa.com
  • kumaru.com
  • gdc-dc.com
  • washinwtonpost.com
  • pɑypɑɩ.com
  • wmlmrt.com
  • www.kakora.com
  • yhoo.com
  • cɩoudfɩare.com
  • de.com
  • gmɑiɩ.com
  • goleleapis.com
  • huffinɡtonpost.com
  • anetsons.net
  • microsoftonɩine.com
  • Mazai.com
  • roidndroid.com
  • netfix.com
  • nvidiɑ.com
  • ɩoogɩe.com

Si iwe unoda kuziva zvimwe zvakawanda nezvazvo pamusoro pekuwanikwa uku, unogona kubvunza chinotevera chinongedzo.


Siya yako yekutaura

Your kero e havazobvumirwi ichibudiswa. Raida minda anozivikanwa ne *

*

*

  1. Inotarisira iyo data: Miguel Ángel Gatón
  2. Chinangwa cheiyo data: Kudzora SPAM, manejimendi manejimendi.
  3. Legitimation: Kubvuma kwako
  4. Kutaurirana kwedata
  5. Dhata yekuchengetedza: Dhatabhesi inobatwa neOccentus Networks (EU)
  6. Kodzero: Panguva ipi neipi iwe unogona kudzora, kupora uye kudzima ruzivo rwako