Hacker News new | past | comments | ask | show | jobs | submit login

> You can make Text-only links look fairly harmless too.

Could you give an example? As far as I know, you cannot do something like making a link look like it belongs to a completely different domain.




Examples from what I've seen:

    https://account:paypal.com.login@verified-account.com/phish
This, to the untrained eye, might at first glance look like a paypal.com link. In fact, it belongs to verified-account.com and it abuses the capability of URLs to contain a username and password to make it look legit.


Wow, I knew Firefox warns for these by default so I thought nobody would ever use this for a phishing attack anymore but it looks like Chrome just meekly follows the standard. That's too bad, really, this is a very easy way to create very realistic phishing mails.


Don't even need that account: at start, this works in chrome:

https://www.paypal.com@google.com


In Firefox it tells me:

    You are about to log in to the site “google.com” with the username “www%2Epaypal%2Ecom”, but the website does not require authentication. This may be an attempt to trick you.
    
    Is “google.com” the site you want to visit?


From the error message it sounds like if this was an attacker controlled site configured to require authentication it wouldn't trigger? If so it's not that useful a defense since whether to require auth is entirely under the attacker's control.


Gold star for Firefox! That's an excellent feature.


I'd say domain name squatting.

For example

https://login.banksofamerica.com


There are a lot of homoglyph url tricks. It turns out there are even online attack generators for these, so you can see for yourself:

https://www.irongeek.com/homoglyph-attack-generator.php

https://adlinkurl.com/blog/2-homoglyph-url-spoofer


glyphs that look similar in most fonts: appIIe[.]com payaI[.]com

They look different in monospace, but I know Gmail renders plaintext mail with a normal sans-serif.

You can also just spell things mildly wrong. People often auto-correct spelling in their mind without realizing it, ex: microsott[.]com

Note I added [] to avoid linking the sites. Those domains look like they're squatted by suspicious customers already.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: