New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 756047 link

Starred by 3 users

Issue metadata

Status: WontFix
Owner:
Closed: Aug 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows , Mac
Pri: 1
Type: Bug-Security
Team-Security-UX



Sign in to add a comment

IDN URL Spoofing

Reported by rayyan...@gmail.com, Aug 16 2017

Issue description

The chrome shows the following website in punnycode only if the TLD is .com 

gmaīl.co ( http://xn--gmal-sya.co/ )

Latin: U+012B
 

----------------------------------------

However, it shows the following web in punnycode whatever the TLD is, therefore, maybe something is wrong here. 

gmaῑl.co  ( http://xn--gmal-nz6a.co/ )

Greek: U+1FD1

 
Components: UI>Security>UrlFormatting UI>Internationalization
Owner: js...@chromium.org
Status: Untriaged (was: Unconfirmed)
Summary: IDN URL Spoofing (was: URL Spoofing)
Project Member

Comment 2 by sheriffbot@chromium.org, Aug 17 2017

Status: Assigned (was: Untriaged)

Comment 3 by rsesek@chromium.org, Aug 17 2017

Labels: Security_Severity-Medium Security_Impact-Stable OS-Mac OS-Windows Pri-1
Project Member

Comment 4 by sheriffbot@chromium.org, Aug 18 2017

Labels: M-61

Comment 5 by js...@chromium.org, Aug 21 2017

Status: WontFix (was: Assigned)
Nothing is wrong.  It's working as intende. 

The second one is blocked because it's mixing Latin and Greek.

The first one is blocked because it looks similar to one of top 10k domains (google.com). 

Comment 6 by js...@chromium.org, Aug 21 2017

correction: 

> The first one is blocked because it looks similar to one of top 10k domains (google.com).

The first one is NOT blocked because its skeleton (similarity skeleton) does not match one of top 10k domains. gmail.com is in the list but gmail.co is not. 


Project Member

Comment 7 by sheriffbot@chromium.org, Nov 28 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: idn-spoof

Sign in to add a comment