¿Crees que puedes fiarte de tus ojos? Un ataque homógrafo crea dominios falsos casi idénticos a los reales. Te enseño cómo funciona el engaño con #Punycode. #Phishing #Ciberseguridad #Ataques
Latest posts tagged with #Punycode on Bluesky
¿Crees que puedes fiarte de tus ojos? Un ataque homógrafo crea dominios falsos casi idénticos a los reales. Te enseño cómo funciona el engaño con #Punycode. #Phishing #Ciberseguridad #Ataques
> […] In their encoded form, IDNs [Internationalized Domain Names] are already valid hostnames, and thus valid handles. […] Applications may, optionally, parse and display IDN handles as Unicode.
atproto.com/specs/handle...
#punycode #handles #IDN #atproto
Critical zero-click vulnerability allows attackers to hijack email accounts via Punycode exploitation. Developers must act now to secure authentication systems. #CyberSecurity #ZeroClick #Punycode Link: thedailytechfeed.com/critical-zer...
That’s not the letter ‘a’... and it could cost you.
Watch this before clicking another link.
Have you ever double-checked a URL before logging in?
#PhishingScam #Punycode #OnlineSafety #TechTips
#Xidax #GamingPC #CustomPC #PCBuilds #RTXGaming #PCGamingCommunity #GameSafe #TechSecurity
This Simple Domain Hack Is Fooling Millions: Don’t Be Next! Cybercriminals are using lookalike ...
infosecwriteups.com/this-simple-domain-hack-...
#cybersecurity #punycode #domains #phishing #hacking
Result Details
#libidn2 2.3.8 has been released ( #libidn / #GNU / #IDNA2008 / #Punycode / #TR46 / #UnicodeTR46 / #IDNA ) gnu.org/software/lib...
Code diff perview on GitHub showing JavaScript code related to handling IDN homograph attacks with comments and highlighted changes.
Code diff preview from a TypeScript file dealing with character handling and language support, including checks for Latin, IPA, Greek, Cyrillic, Armenian, and NKo scripts.
ugh… like seriously? https://github.com/bluesky-social/social-app/pull/7043
This is from BlueSky's side (their own set of issues), but does Mastodon/AP need this too? 🤔
#Punycode #IDN
FWIW, here’s a presentation I did on #Punycode, Internationalised Domain Names, and such. From 2010s, but a lot still applies today. #IDN
NB: IDNs are not evil, but can be used to deceive people. E.g., Homoglyph exploits.
www.slideshare.net/slideshow/in...
#IDN test
☺.bsky.social ←dragNdrop = xn--74h.bsky.social
#InternationalizedDomainName
X displays the unicode character, instead the #punycode
Malvertising:
#KeePass-Seite mit #Punycode gefälscht
Cyberkriminelle werben über Google Ads etwa mit gefälschten KeePass-URLs mit Punycode-Zeichen. Die beworbene Seite liefert #Malware aus.
#WTF
www.heise.de/news/Malvert...
We thought the #IDN / #Punycode menace had been quashed, but it appears not.
The rogue Latvian glyph looks like a speck of dust on your screen—under the ķ. In today’s #SBBlogwatch, we blow it off. At @TechstrongGroup’s @SecurityBlvd: securityboulevard.com/2023/10/keep...
𒀱 #idn #idnOWL #streetART #invalidBEACH #Berlin 𒀱
don't be scared → xn--wta3hb403ica11187ama.tk #punycode ( X → ﴾͡๏̯͡๏﴿.tk )
instagr.am/idnOWL