New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 802131 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 770709
Owner:
Closed: Jan 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security
Team-Security-UX



Sign in to add a comment

Security: ṇ (n with dot below) used for URL Spoofing

Reported by joseph.s...@gmail.com, Jan 16 2018

Issue description

VULNERABILITY DETAILS

You should provide a warning on any URL containing the character ṇ
Right now, links to such URLs produce no warning, and often have the dot obscured by the underline common under web links - www.citibaṇk.com appears as if it were www.citibank.com, but it is not. I am sure you understand the potential consequences of criminals using such domains for phishing attacks and the like.

VERSION
Chrome Version: ALL
Operating System: ALL

REPRODUCTION CASE
Please include a demonstration of the security bug, such as an attached
HTML or binary file that reproduces the bug when loaded in Chrome. PLEASE
make the file as small as possible and remove any content not required to
demonstrate the bug.

Type www.citibaṇk.com into your browser and you will see...

 
Components: UI>Security>UrlFormatting UI>Internationalization
Labels: Needs-Feedback
Summary: Security: ṇ (n with dot below) used for URL Spoofing (was: Security: )
In what browser version do you see this render as an n with a dot under it in the omnibox?

In Chrome 63 and Chrome 64, it renders as xn--citibak-u13c.com as expected.
Owner: js...@chromium.org
This is probably duplicate of  Issue 770709 . jshin@, can you confirm?

Comment 3 by js...@chromium.org, Jan 16 2018

Mergedinto: 770709
Status: Duplicate (was: Unconfirmed)
Yes, but citibank.com is ok as you mentioned in comment 1. 


In Version 63.0.3239.132 (Official Build) (64-bit)
when I type or paste
goldmaṇsachs.com
into the browser, the browser shows
goldmaṇsachs.com
loads the page, and still shows
goldmaṇsachs.com
in the box. 

Note: I received a phishing email earlier this week using this technique. 
GoldmanSachs3-Chrome.png
323 KB View Download
Project Member

Comment 7 by sheriffbot@chromium.org, Aug 25

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: idn-spoof

Sign in to add a comment