I-bug ivunyelwe ukubhalisa imimandla ye-phishing ngabalinganiswa be-Unicode

iwebhsayithi yobuqhetseba

Kwiintsuku ezimbalwa ezidlulileyo Abaphandi be-Soluble babhengeze ukufunyanwa kwabo okutsha de indlela entsha yokubhalisa imimandla kunye ne-homoglyphs ekhangeleka ifana neminye imimandla, kodwa eneneni yahluka ngenxa yobukho babalinganiswa abanentsingiselo eyahlukileyo.

Le mimandla yamazwe ngamazwe (IDN) inokuthi ekuqaleni ayifani ukusuka kwimimandla yeenkampani kunye neenkonzo ezaziwayo, ezikuvumela ukuba uzisebenzise ukukhohlisa, kuquka ukufumana izatifikethi ezichanekileyo ze-TLS kubo.

Ukubhaliswa okuyimpumelelo kwale mimandla kujongeka njengemimandla echanekileyo kwaye ziyaziwa, kwaye zisetyenziselwa ukwenza uhlaselo lobunjineli bezentlalo kwimibutho.

UMat Hamilton, umphandi kwi-Soluble, uchonge ukuba kunokwenzeka ukubhalisa iindawo ezininzi imimandla yomgangatho ophezulu jikelele (gTLDs) isebenzisa i-Unicode Latin IPA uphawu lolwandiso (olufana ne ɑ kunye ne ɩ), kwaye ikwazile ukubhalisa le mimandla ilandelayo.

Ukutshintshwa kweClassic ngokusebenzisa i-IDN ebonakala ngathi idomeyini ivaliwe ixesha elide kwiziphequluli kunye neerejistra, ngenxa yokuthintela ukuxuba abalinganiswa kwiialfabhethi ezahlukeneyo. Umzekelo, indawo yobuxoki apple.com ("xn--pple-43d.com") ayinakwenziwa ngokususa isiLatini esithi "a" (U+0061) ngesiCyrillic "a" (U+0430), okoko kuxutywa. ukuqonda koonobumba abasuka kwii-alfabhethi ezahlukeneyo akuvumelekanga.

Ngo-2017, indlela yokudlula olu khuselo yafunyanwa ngokusebenzisa kuphela oonobumba beyunicode kwidomeyini, ngaphandle kokusebenzisa ialfabhethi yesiLatini (umzekelo, ukusebenzisa abasebenzi bolwimi abanamagama afana nesiLatini).

Ngoku enye indlela yokudlula ukhuseleko ifunyenwe, ngokusekelwe kwinto yokuba ababhalisi bavimba i Umxube wesiLatini kunye ne-Unicode, kodwa ukuba iimpawu ze Unicode ezikhankanyiweyo kwindawo yolawulo ngabeqela labasebenzi besiLatini, ukuxuba okunjalo kuvumelekile, kuba iimpawu zingabealfabhethi enye.

Ingxaki kukuba i-Unicode Latin IPA extension iqulethe iihomoglyphs ezifanayo kupelo kwabanye oonobumba besiLatini: isimboli «ɑ» ifana «a», «ɡ» -» g», «ɩ» – «l».

Ithuba lokubhalisa i-domain apho isiLatini sixutywe kunye neempawu ze-Unicode ezibonakalisiweyo zichongiwe kunye nombhalisi we-Verisign (abanye ababhalisi abazange baqinisekiswe), kwaye ii-subdomains zenziwa kwiinkonzo ze-Amazon, i-Google, i-Wasabi kunye ne-DigitalOcean.

Nangona uphando lwenziwa kuphela kwi-gTLDs elawulwa yi-Verisign, ingxaki Ayizange ithathelwe ngqalelo zizigebenga zenethiwekhi kwaye ngaphandle kwezaziso ezithunyelweyo, kwiinyanga ezintathu kamva, ngomzuzu wokugqibela, yasonjululwa kuphela kwi-Amazon kunye neVerisign kuba ngabo kuphela abayithathayo ingxaki kakhulu.

UHamilton ugcine ingxelo yakhe ngasese. kude kube yi-Verisign, inkampani elawula ukubhaliswa kwesizinda kwi-domain yezinga eliphezulu elivelele (gTLD) njenge-.com kunye ne-.net, yalungisa ingxaki.

Abaphandi baye baqalisa inkonzo ye-intanethi ukuqinisekisa imimandla yakho ukukhangela iindlela ezizezinye ezinokubakho ngee-homoglyphs, kubandakanywa ukuqinisekiswa kwemimandla esele ibhalisiwe kunye nezatifikethi ze-TLS ezinamagama afanayo.

Ngokumalunga nezatifikethi ze-HTTPS, ngeerekhodi zeSatifikethi sokuNgafihlisi, imimandla ye-300 ene-homoglyphs yaqinisekiswa, apho i-15 ibhalisiwe kwisizukulwana sezatifikethi.

Iibhrawuza zokwenyani zeChrome kunye neFirefox zibonakalisa imimandla efanayo kwibha yedilesi kwinqaku elinesimaphambili "xn--", nangona kunjalo, imimandla ibonwa ngaphandle kokuguqulwa kwamakhonkco, anokusetyenziswa ukufaka izixhobo ezinobungozi okanye amakhonkco kumaphepha, phantsi Isizathu sokuzikhuphela kwiindawo ezisemthethweni.

Ngokomzekelo, kwelinye lemimandla echongiweyo ngee-homoglyphs, ukusasazeka kwenguqulelo engalunganga yelayibrari ye-jQuery yarekhodwa.

Ngexesha lokulinga, Abaphandi bachitha i-$ 400 kwaye babhalise le mimandla elandelayo kunye neVerisign:

  • amzon.com
  • chsese.com
  • slesolinenecuba.com
  • Ndibulele.com
  • .comppɩe.com
  • ebyy.com
  • .comstatic.com
  • zintsi.com
  • elokuni.com
  • leendek.com
  • lucangcube.com
  • oyifumi.com
  • lungelcom.com
  • wssbisys.com
  • yuhoo.com
  • lungelojk.com
  • deɩɩ.com
  • yifumni.com
  • www.gooɡleapis.com
  • huffinkhangela.com
  • zeksiva.com
  • microsoftonɩine.com
  • ɑmɑzonɑws.com
  • roidndroid.com
  • netfix.com
  • nvidiɑ.com
  • .comoogɩe.com

Si Ngaba uyafuna ukwazi iinkcukacha ezithe vetshe ngayo? malunga noku kufunyaniswa, ungabonisana eli khonkco lilandelayo.


Shiya uluvo lwakho

Idilesi yakho ye email aziyi kupapashwa. ezidingekayo ziphawulwe *

*

*

  1. Uxanduva lwedatha: UMiguel Ángel Gatón
  2. Injongo yedatha: Ulawulo lwe-SPAM, ulawulo lwezimvo.
  3. Umthetho: Imvume yakho
  4. Unxibelelwano lwedatha: Idatha ayizukuhanjiswa kubantu besithathu ngaphandle koxanduva lomthetho.
  5. Ukugcinwa kweenkcukacha
  6. Amalungelo: Ngalo naliphi na ixesha unganciphisa, uphinde uphinde ucime ulwazi lwakho.