Security: IDN URL Spoofing with “ก”
Reported by
chromium...@gmail.com,
Sep 8
|
||||||||||||||||||||
Issue descriptionVERSION Chrome Version: 71.0.3545.3 (Official Build) canary (64-bit) Operating System: Mac REPRODUCTION CASE Visit http://xn--11-lqi.com/ - U+0E01 (ก) is more similar to 'n' Note: n11.com is a top-10K site.
,
Sep 9
,
Sep 10
,
Sep 10
,
Sep 12
I have a quick CL up to add this to the confusables list while meacer is OOO: https://chromium-review.googlesource.com/c/chromium/src/+/1220773
,
Sep 14
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/3983030c2ee3e54afa60fe24f23e4c98067a3634 commit 3983030c2ee3e54afa60fe24f23e4c98067a3634 Author: Christopher Thompson <cthomp@chromium.org> Date: Fri Sep 14 00:30:39 2018 Add additional Lao character to IDN confusables U+0E01 (ก) => n Prior Lao/Thai entries were added in crrev.com/c/1058710. Test: components_unittests --gtest_filter=*IDN* Bug: 882078 Change-Id: I1e90b144a1d791341b515d026a6bc4be7cbed57d Reviewed-on: https://chromium-review.googlesource.com/1220773 Reviewed-by: Peter Kasting <pkasting@chromium.org> Commit-Queue: Christopher Thompson <cthomp@chromium.org> Cr-Commit-Position: refs/heads/master@{#591227} [modify] https://crrev.com/3983030c2ee3e54afa60fe24f23e4c98067a3634/components/url_formatter/idn_spoof_checker.cc [modify] https://crrev.com/3983030c2ee3e54afa60fe24f23e4c98067a3634/components/url_formatter/top_domains/alexa_domains.skeletons [modify] https://crrev.com/3983030c2ee3e54afa60fe24f23e4c98067a3634/components/url_formatter/top_domains/test_domains.list [modify] https://crrev.com/3983030c2ee3e54afa60fe24f23e4c98067a3634/components/url_formatter/top_domains/test_domains.skeletons [modify] https://crrev.com/3983030c2ee3e54afa60fe24f23e4c98067a3634/components/url_formatter/url_formatter_unittest.cc
,
Sep 14
,
Sep 14
,
Sep 17
,
Sep 18
,
Sep 18
This bug requires manual review: Less than 24 days to go before AppStore submit on M70 Please contact the milestone owner if you have questions. Owners: benmason@(Android), kariahda@(iOS), geohsu@(ChromeOS), abdulsyed@(Desktop) For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Sep 18
,
Sep 19
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/db0a0dfdc697039796e2b955dbaa01ffce2fb16b commit db0a0dfdc697039796e2b955dbaa01ffce2fb16b Author: Christopher Thompson <cthomp@chromium.org> Date: Tue Sep 18 23:59:03 2018 [M70] Add additional Lao character to IDN confusables U+0E01 (ก) => n Prior Lao/Thai entries were added in crrev.com/c/1058710. Test: components_unittests --gtest_filter=*IDN* Bug: 882078 Change-Id: I1e90b144a1d791341b515d026a6bc4be7cbed57d Reviewed-on: https://chromium-review.googlesource.com/1220773 Reviewed-by: Peter Kasting <pkasting@chromium.org> Commit-Queue: Christopher Thompson <cthomp@chromium.org> Cr-Original-Commit-Position: refs/heads/master@{#591227}(cherry picked from commit 3983030c2ee3e54afa60fe24f23e4c98067a3634) Reviewed-on: https://chromium-review.googlesource.com/1232679 Reviewed-by: Christopher Thompson <cthomp@chromium.org> Cr-Commit-Position: refs/branch-heads/3538@{#514} Cr-Branched-From: 79f7c91a2b2a2932cd447fa6f865cb6662fa8fa6-refs/heads/master@{#587811} [modify] https://crrev.com/db0a0dfdc697039796e2b955dbaa01ffce2fb16b/components/url_formatter/idn_spoof_checker.cc [modify] https://crrev.com/db0a0dfdc697039796e2b955dbaa01ffce2fb16b/components/url_formatter/top_domains/alexa_domains.skeletons [modify] https://crrev.com/db0a0dfdc697039796e2b955dbaa01ffce2fb16b/components/url_formatter/top_domains/test_domains.list [modify] https://crrev.com/db0a0dfdc697039796e2b955dbaa01ffce2fb16b/components/url_formatter/top_domains/test_domains.skeletons [modify] https://crrev.com/db0a0dfdc697039796e2b955dbaa01ffce2fb16b/components/url_formatter/url_formatter_unittest.cc
,
Oct 4
*** Boilerplate reminders! *** Please do NOT publicly disclose details until a fix has been released to all our users. Early public disclosure may cancel the provisional reward. Also, please be considerate about disclosure when the bug affects a core library that may be used by other products. Please do NOT share this information with third parties who are not directly involved in fixing the bug. Doing so may cancel the provisional reward. Please be honest if you have already disclosed anything publicly or to third parties. Lastly, we understand that some of you are not interested in money. We offer the option to donate your reward to an eligible charity. If you prefer this option, let us know and we will also match your donation - subject to our discretion. Any rewards that are unclaimed after 12 months will be donated to a charity of our choosing. *********************************
,
Oct 4
$500 for this one!
,
Oct 4
,
Oct 15
,
Oct 16
,
Oct 19
,
Oct 19
,
Nov 12
,
Dec 21
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||||||||||||||||||
►
Sign in to add a comment |
||||||||||||||||||||
Comment 1 by chromium...@gmail.com
, Sep 8