Home / Blogs

IDN and Homographs Spoofing

James Seng

There is a published spoofing attack using homographs IDN. By using a Cyrillic SMALL LETTER A (U+430), Securnia is able to pretend to be http://www.paypal.com/.

Actually this is well-documented in RFC 3490 under the Security Consideration:

"To help prevent confusion between characters that are visually similar, it is suggested that implementations provide visual indications where a domain name contains multiple scripts.  Such mechanisms can also be used to show when a name contains a mixture of simplified and traditional Chinese characters, or to distinguish zero and one from O and l.  DNS zone adminstrators may impose restrictions (subject to the limitations in section 2) that try to minimize homographs."

The problem is that many of the current IDN implementations did not provide any indication that it is an IDN names (instead of a normal one). In fact, Mark Davis1 published a snipplet of code to demostrate how to do despoofing in 2002.

But the fact Secunia is able to register paypal.com (with Cyrillic a), ie xn--pypal-4ve.com begs a question - why are they able to do so?

Even though we have been asking Verisign registry to implement RFC 3743 (aka JET Guidelines) or to follow ICANN IDN Guidelines (specifically on language tag) for many years, they have not done so, and instead opt to allow any IDN strings to be registered. This homographs spoofing attack would not be possible if Verisign have done appropriate step to associate each registered internationalized domain name with one language or set of languages and employ language-specific registration and administration rules that are documented and publicly available (as recommended by ICANN IDN Guideline).

Now, given Verisign is a security company, the "Trust Company", and they have been following the IDN standardization work from the beginning, I am sure this is well-known to them. Lets hope this report will help change their position before a real phishing attack occurs.

1 Mark Davis is the president of Unicode Consortium.

By James Seng, Assistant Director. Visit the blog maintained by James Seng here.

Related topics: DNS, Domain Names, ICANN, Multilinguism, Security

Get a weekly summary of postings to CircleID:

 Master Feed (more feeds)      Twitter      Mobile
Bookmark / Email This Post

Comments

Re: IDN and Homographs Spoofing Geoffrey Sisson  –  Feb 08, 2005 5:22 AM PDT

While limiting IDN labels to codepoints associated with a single language (as per the ICANN IDN guidelines and RFC 3743) does significantly mitigate the problem, it does not eliminate it.  For example the first label in ѕе&#x0445.com contains Cyrillic codepoints only, yet in many browsers is easily confused with its US-ASCII equivalent.  This isn't an indictement of the guidelines, just a warning that they should not be viewed as a magic bullet.

Re: IDN and Homographs Spoofing Geoffrey Sisson  –  Feb 08, 2005 5:44 AM PDT

[ The link in my previous comment was incorrectly rendered; it should have been: ѕех.com ]

Re: IDN and Homographs Spoofing James Seng  –  Feb 08, 2005 7:45 PM PDT

Update: Mark Davis poined out a UTR #36 Security Consideration for Implementation of Unicode and other Related Technologies.

Ben Laurie pointed out I have incorrectly attribute the IDN spoofing to Securnia - it was Eric Johnson.

Re: IDN and Homographs Spoofing James Seng  –  Feb 17, 2005 5:07 PM PDT

Update: Found a better reference to the idea Mark Davis proposed back in 2002.

Re: IDN and Homographs Spoofing Jerry Burns  –  Mar 01, 2006 9:40 PM PDT

I own the Cyrillic IDN you list (not paypal).  I bought it for fun, not phishing, like buying a fake Rolex that I would never wear. I hate to sound defensive, but you are certainly not the only one to pick on that one domain. It does not pretend to be the original site.  Phony bank, credit card, etc sites and scum/spyware are the real threat. 

Thanks for mentioning paypal, but why pick on my site?  There are several variations of triple X, xbox, xp dot com and many other IDN sites.  If someone registers an ASCII domain name with the word "Microsoft" in it, they are likely to be sued if they use it to deceive. Let the current system handle it along with MS IE7 and other anti-phishing software.

To post comments, please login or create an account.

Related Blogs

Domain Registrars & Registries: Don't Say You Weren't Warned

EoWhy?

Perspectives on a DNS-CERT

"Thin Brand Line" Breaks as Canon Announces Plans for .CANON

EI, EI - NO!

Related News

Other Topics

Access Providers Broadband Censorship Cloud Computing Cyberattack Cybercrime Cybersquatting Data Center DNS DNSSEC Domain Names Domain Registries Email Enum ICANN Internet Governance Internet Protocol IP Addressing IPTV IPv6 Law Malware Mobile Multilinguism Net Neutrality P2P Policy & Regulation Privacy Regional Registries Security Spam Telecom Top-Level Domains VoIP Web White Space Whois Wireless



Industry Updates – Sponsored Posts

.ORG, The Public Interest Registry Celebrates Its 25th Year With 8 Million Registrations

MarkMonitor Year in Review Report: How Escalating Online Brand Abuse is Used to Monetize Web Traffic

.ORG: Introducing Fully Internationalized Domain Names

.ORG to Fully Deploy DNSSEC in June

The GLOBE Program Chooses Dyn Inc.'s Dynect Platform to Deploy DNSSEC per Federal OMB Mandate

SPECIAL: Updates from the ICANN Meetings in Nairobi

.ORG Registrations in 2009 Grew 8.4 Percent Over Previous Year

MarkMonitor Sets New Standard in Brand Protection with Site Staydown Service

Announcement: dotMobi Ownership

Afilias Limited Acquires .Mobi Domain Registry, Expands Market Leadership

ICANN and Cybersecurity: Hot Topics at The First Ever .ORG Forum

Using .ORG Directory to Find Haiti Relief Organizations

Neustar Releases UltraDNS Report Center

Afilias Releases .INFO Domain 2009 Annual Report

Expressions of Interest a Requirement for New gTLDs?

Neustar Implements DNS Security Extensions in the .US Registry

Neustar Launches Initiative to Enhance DNS With Faster, More Secure Updates

Registry Stakeholder Group Comments on Latest ICANN Policies

Open Phishing Season

dotMobi Is Now a Member of The LACTLD