New issue
Advanced search Search tips

Issue 774253 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 773930
Owner: ----
Closed: Oct 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: IDN punycode not displayed for misleading cyrillic .com domain

Reported by calderon...@gmail.com, Oct 12 2017

Issue description

VULNERABILITY DETAILS
Browsing to a non-latin ".com" domain with cyrillic character isn't displayed in it's punycode version.

Hence, users which have been tricked into clicking on the phishing link will be show the misleading address in the URL bar.
As said in previous reports, this is problematic in many ways and the current set of forbidden characters for ".com" domains isn't complete enough or is not working as intended.

I registered today the following domain: xn--x1aaa.xn--80aa1boaj3b9g.com which maps to шнатѕарр.com.

I was expecting the punycode version to be displayed but this is not the case on MacOS, Linux and Android. I was also able to get a Let's Encrypt certificate for this domain which allows me to browse it using HTTPS.


VERSION
Chrome Version: Version 61.0.3163.100 (Official Build) (64-bit) / Version 61.0.3163.98 (Android)

Operating System: OSX 10.11.6 (15G31) / Ubuntu Linux 16.04 LTS amd64 / Android 7

REPRODUCTION CASE
Browse the following url: https://шнатѕарр.com
 
Screen Shot 2017-10-12 at 22.35.06.png
138 KB View Download
Screen Shot 2017-10-12 at 22.36.14.png
70.7 KB View Download
Cc: js...@chromium.org
Components: UI>Browser>Omnibox UI>Internationalization
Status: Untriaged (was: Unconfirmed)
Duplicate of  Issue 773930 .
I do not have access to  Issue 773930 .

Comment 3 by kenrb@chromium.org, Oct 17 2017

Mergedinto: 773930
Status: Duplicate (was: Untriaged)
Hey there, is it possible to grant me access to #773930 so that I can follow the discussion there given my issue has been merge with it?
Project Member

Comment 5 by sheriffbot@chromium.org, Apr 13 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: idn-spoof

Sign in to add a comment