The ability to register phishing domains with similar unicode characters in the name

Researchers from Soluble identified a new way to register domains with homoglyphs, which externally resemble other domains but actually differ due to the presence of characters with different meanings. Such internationalized domains (IDN) may initially appear indistinguishable from domains of well-known companies and services, allowing them to be used for phishing, even obtaining valid TLS certificates for them.

Classic spoofing through visually similar IDN domains has long been blocked by browsers and registrars due to the prohibition against mixing characters from different alphabets. For example, a spoofed domain a pple.com ("xn--pple-43d.com") cannot be created by replacing the Latin 'a' (U+0061) with the Cyrillic 'а' (U+0430), as mixing letters from different alphabets in a domain is not allowed. In 2017, there was found a way to bypass such protection through the use of only Unicode characters in the domain, without the use of Latin letters (for instance, using characters from languages with symbols similar to Latin).

Now another method of bypassing protection has been found, based on the fact that registrars block mixing Latin characters and Unicode, but if the specified Unicode characters in the domain belong to the group of Latin characters, such mixing is permitted, as the characters belong to one alphabet. The problem is that in the Unicode Latin IPA extension there are homoglyphs that look similar to other characters of the Latin alphabet:
the character "ɑ" resembles "a", "ɡ" — "g", "ɩ" — "l".

The ability to register phishing domains with similar unicode characters in the name

The ability to register domains that mix Latin characters with the specified Unicode characters has been identified in the registrar Verisign (other registrars were not checked), and subdomains were created in services like Amazon, Google, Wasabi, and DigitalOcean. The issue was discovered last November and, despite notifications sent, was only resolved at the last moment in Amazon and Verisign three months later.

During the experiment, researchers spent $400 to register the following domains in Verisign:

  • amɑzon.com
  • chɑse.com
  • sɑlesforce.com
  • ɡmɑil.com
  • ɑppɩe.com
  • ebɑy.com
  • ɡstatic.com
  • steɑmpowered.com
  • theɡuardian.com
  • theverɡe.com
  • washinɡtonpost.com
  • pɑypɑɩ.com
  • wɑlmɑrt.com
  • wɑsɑbisys.com
  • yɑhoo.com
  • cɩoudfɩare.com
  • deɩɩ.com
  • gmɑiɩ.com
  • gooɡleapis.com
  • huffinɡtonpost.com
  • instaɡram.com
  • microsoftonɩine.com
  • ɑmɑzonɑws.com
  • ɑndroid.com
  • netfɩix.com
  • nvidiɑ.com
  • ɡoogɩe.com

Researchers also launched an online service to check your domains for possible alternative variants with homographs, including checking already registered domains and TLS certificates with similar names. As for HTTPS certificates, 300 homograph domains were verified through Certificate Transparency logs, among which 15 had certificate generation recorded.

Current browsers like Chrome and Firefox display such domains in the address bar with the prefix notation 'xn--', however, in links, the domains appear untransformed, which can be exploited to insert them on malicious resource pages or links, posing as legitimate sites. For example, one of the identified homograph domains was noted for distributing a malicious version of the jQuery library.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster