Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you're interested in this... https://en.wikipedia.org/wiki/Homoglyph


Also recently spotted as an avenue for attack in the wild:

Magecart group uses homoglyph attacks to fool you into visiting malicious websites: https://www.zdnet.com/article/magecart-group-uses-homoglyph-...

Homoglyph attacks used in phishing campaign and Magecart attacks https://securityaffairs.co/wordpress/106916/hacking/homoglyp...

https://cisomag.eccouncil.org/homoglyph-attacks/


You can easily avoid homoglyph attacks or similar stuff by following the relevant unicode security considerations. I'm on Moderately Restrictive level for General Security Profile for identifiers. http://perl11.org/blog/unicode-identifiers.html

Forbidding mixed scripts fixes this attack. You also need to normalized names, and a few more minor things.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: