Security: Whole-script confusable domain label spoofing (Cyrillic)
Reported by
chromium...@gmail.com,
Feb 20 2018
|
||||||||||||||||||||||
Issue descriptionVERSION Chrome Version: 66.0.3350.0 (Official Build) canary (64-bit) Operating System: All REPRODUCTION CASE https://xn--80aa2cah8a7f79b.com is shown https://шӊатѕарр.com Note: This is similar to issue 793628 .
,
Feb 20 2018
I think so, since https://xn--80aa1boaj3b9g.com is shown as expected.
,
Feb 20 2018
,
Feb 20 2018
Thanks for the report. U+04CA (ӊ) was missed in bug 793628 because it didn't look like capital H with a font (Symbola ) that happenen to render the character in https://goo.gl/orKdsQ for the following set. (the Unicode util page specifies a bunch of fonts and the first one covering U+04CA was 'symbola' with a rather unusual shape for U+04CA). [:IdentifierStatus=Allowed:] & [:Ll:] & [[:sc=Cyrillic:] - [[\u01cd-\u01dc][\u1c80-\u1c8f][\u1e00-\u1e9b][\u1f00-\u1fff] [\ua640-\ua69f][\ua720-\ua7ff]]] & [:NFD_Inert=Yes:]
,
Feb 21 2018
,
Feb 21 2018
,
Feb 21 2018
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/d52b8375cfe5b56194d3df09c18e7b64e5838369 commit d52b8375cfe5b56194d3df09c18e7b64e5838369 Author: Jungshik Shin <jshin@chromium.org> Date: Wed Feb 21 18:40:39 2018 Add a few more entries to the confusables list for IDN U+04CA (ӊ) => h U+0E1F (ฟ) => w U+0E23 (ร) => s Bug: 813925, 813814 Test: components_unittests --gtest_filter=*IDN* Change-Id: If81ea9bf1c1729f1b6ffc71d718dc5950ac825b5 Reviewed-on: https://chromium-review.googlesource.com/927741 Reviewed-by: Peter Kasting <pkasting@chromium.org> Commit-Queue: Jungshik Shin <jshin@chromium.org> Cr-Commit-Position: refs/heads/master@{#538159} [modify] https://crrev.com/d52b8375cfe5b56194d3df09c18e7b64e5838369/components/url_formatter/idn_spoof_checker.cc [modify] https://crrev.com/d52b8375cfe5b56194d3df09c18e7b64e5838369/components/url_formatter/top_domains/test_domains.list [modify] https://crrev.com/d52b8375cfe5b56194d3df09c18e7b64e5838369/components/url_formatter/top_domains/test_skeletons.gperf [modify] https://crrev.com/d52b8375cfe5b56194d3df09c18e7b64e5838369/components/url_formatter/url_formatter_unittest.cc
,
Feb 22 2018
,
Feb 24 2018
,
Feb 26 2018
,
Mar 6 2018
,
Mar 6 2018
*** Boilerplate reminders! *** Please do NOT publicly disclose details until a fix has been released to all our users. Early public disclosure may cancel the provisional reward. Also, please be considerate about disclosure when the bug affects a core library that may be used by other products. Please do NOT share this information with third parties who are not directly involved in fixing the bug. Doing so may cancel the provisional reward. Please be honest if you have already disclosed anything publicly or to third parties. Lastly, we understand that some of you are not interested in money. We offer the option to donate your reward to an eligible charity. If you prefer this option, let us know and we will also match your donation - subject to our discretion. Any rewards that are unclaimed after 12 months will be donated to a charity of our choosing. *********************************
,
Mar 7 2018
Thanks! $500 for this.
,
Mar 7 2018
,
Mar 16 2018
,
Mar 16 2018
This bug requires manual review: Less than 28 days to go before AppStore submit on M66 Please contact the milestone owner if you have questions. Owners: cmasso@(Android), cmasso@(iOS), josafat@(ChromeOS), abdulsyed@(Desktop) For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Mar 19 2018
Please verify the fix in the latest canary
,
Mar 19 2018
verified on canary 67.0.3375.0, https://шӊатѕарр.comis is shown in punycode as expected.
,
Mar 19 2018
,
Mar 20 2018
The CL for this bug was landed on Feb 21 (a week before 66 branch). See comment 7.
,
Mar 20 2018
,
Apr 17 2018
,
Apr 25 2018
,
Apr 25 2018
,
Jun 1 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 19
,
Dec 4
|
||||||||||||||||||||||
►
Sign in to add a comment |
||||||||||||||||||||||
Comment 1 by elawrence@chromium.org
, Feb 20 2018Components: UI>Security>UrlFormatting UI>Internationalization