New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 791356 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 791336
Owner:
Closed: Dec 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: URL IDN spoofing

Reported by chromium...@gmail.com, Dec 3 2017

Issue description

VERSION
Chrome Version: 64.0.3282.5
Operating System: All

REPRODUCTION CASE

This http://xn--twtter-j8a.com/ should be blocked on Chrome because it's mixing Latin, and twitter.com is in the top 10k domains list.

Also: http://xn--wndows-i8a.com/
 
Cc: js...@chromium.org
Components: UI>Browser>Omnibox UI>Internationalization
Status: Untriaged (was: Unconfirmed)
Interestingly, the Twitter spoof is blocked in Chrome 63 but not Chrome 64.
Ah! I did not notice that.

Chrome M63.png
131 KB View Download
Chrome M64.png
101 KB View Download
Cc: -js...@chromium.org mgiuca@chromium.org
Labels: M-64 Security_Severity-Low Security_Impact-Head
Owner: js...@chromium.org
Status: Assigned (was: Untriaged)

Comment 4 by js...@chromium.org, Dec 4 2017

Mergedinto: 791336
Status: Duplicate (was: Assigned)
This is a dupe of  bug 791336 . It's already fixed in ToT. 
I'm still able to repro this with https://www.xn--doubleclckbygoogle-cxc.com and http://xn--wndows-i8a.com on ToT (65.0.3284.0), while I couldn't repro with http://xn--twtter-j8a.com.
Screen Shot 2017-12-04 at 02.56.31.png
110 KB View Download

Comment 7 by js...@chromium.org, Dec 4 2017

My fix has not made it to the latest canary build, yet. 

Comment 8 by js...@chromium.org, Dec 4 2017

Sorry I misunderstood comment 6. The fix for top domains with 'w' must be included in 65.0.3284.0. 

> www.doubleclīckbygoogle.com 
  
doubleclickbygoogle.com is not in the top domain list. 

> wīndows.com

Neither is windows.com.  

It's a known limitation that there's no easy way  to tell which is legitimate and which is not for those cases on the *Chrome's end*. 


Project Member

Comment 9 by sheriffbot@chromium.org, Mar 12 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: idn-spoof

Sign in to add a comment