国产三级大片在线观看-国产三级电影-国产三级电影经典在线看-国产三级电影久久久-国产三级电影免费-国产三级电影免费观看

Set as Homepage - Add to Favorites

【phim sex 100】Major domain name bug allowed hackers to register malicious domains

Source:Feature Flash Editor:explore Time:2025-07-03 02:35:16

Thanks to a bug at some of the internet’s largest domain registrars,phim sex 100 bad actors were able to register malicious domains until just late last month.

If I told you to click this on this URL, amɑzon.com, and login for a great limited time deal over at Amazon, would you notice it wasn’t reallyAmazon’s domain name?

Hover over it, give it a click. You’ll find that it actually directs you to xn--amzon-1jc.com. Why? Look closely and you’ll notice that the second “a” and the “o” aren’t actually the letters “a” and “o” from the Latin alphabet, which is what’s used in the English language.

It’s not supposed to be possible to register these domain names due to the malicious attacks they could be used for. Many web browsers change the characters in the URL from Unicode to Punycode, as seen in the earlier example, for that very reason.

The zero-day, or previously unknown, bug was discoveredby Matt Hamilton, a security researcher at Soluble, in partnership with the security firm Bishop Fox.

According to Hamilton’s research, he was able to register dozens of names using Latin homoglyphs, basically a character that looks like another character. Verisign, Google, Amazon, DigitalOcean, and Wasabi were among the affected companies allowing the registration of these names.

“Between 2017 and today, more than a dozen homograph domains have had active HTTPS certificates,” writes Hamilton. “This included prominent financial, internet shopping, technology, and other Fortune 100 sites. There is no legitimate or non-fraudulent justification for this activity.”

Hamilton held his report for publication until Verisign, the company that runs the domain registries for prominent general top level domain (gTLD) extensions like .com and .net, fixed the issue. The research was only conducted on gTLDs run by Verisign. He states that among all the vendors he contacted, Amazon and Verisign in particular took the issue very seriously.

Mashable Light Speed Want more out-of-this world tech, space and science stories? Sign up for Mashable's weekly Light Speed newsletter. By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy. Thanks for signing up!

In the Cyrillic alphabet specifically, there are a number of letters that look nearly identical to letters in the Latin alphabet. For example, here’s the character for “a” in Latin. Here’s the character for “ɑ” in Cyrillic.

Combining these homoglyph characters with the Latin alphabet in a domain name could create a URL that looks very much like one that’s already registered by another company, such as fake Amazon domain mentioned earlier.

Hackers could use these domain names to create phishing websites that look like legitimate sites for services like Gmail or PayPal. The attack could steal a users website password or credit card information using this information.

Hamilton was able to register the following domain names thanks to this bug:

amɑzon.com

chɑse.com

sɑlesforce.com

ɡmɑil.com

ɑppɩe.com

ebɑy.com

ɡstatic.com

steɑmpowered.com

theɡuardian.com

theverɡe.com

washinɡtonpost.com

pɑypɑɩ.com

wɑlmɑrt.com

wɑsɑbisys.com

yɑhoo.com

cɩoudfɩare.com

deɩɩ.com

gmɑiɩ.com

gooɡleapis.com

huffinɡtonpost.com

instaɡram.com

microsoftonɩine.com

ɑmɑzonɑws.com

ɑndroid.com

netfɩix.com

nvidiɑ.com

ɡoogɩe.com

In total, he spent $400 to register the domain names that could be used to scam people out of much, much more.

Internationalized domain names, or IDNs, have become popular in recent years. These domains allow users around the world to register names using their native language, such as Greek or Japanese, where you may find non-Latin characters.

However, malicious actors quickly discovered ways to use IDNs for attacks.

SEE ALSO: Rudy Giuliani's typo-filled tweets are catnip for hackers spreading malware

As Bleeping Computerpoints out, the Internet Corporation for Assigned Names and Numbers (ICANN), the organization that manages the web's domain name system, has IDN guidelines state that domain registrars should not allow domains be registered using a combination of different alphabets for this very reason.

It's not a new practice, though. The Registernotes how homograph attacks have been an issue for the web for 15 years.

As for amɑzon.com, or should I say xn--amzon-1jc.com, Hamilton has since transferred the domain to Amazon, the company that can be found at the real amazon.com.

Related Video: Beware of cybercriminals who are taking advantage of coronavirus fears with fake websites and phishing schemes

Topics Cybersecurity

0.1634s , 8178.7109375 kb

Copyright © 2025 Powered by 【phim sex 100】Major domain name bug allowed hackers to register malicious domains,Feature Flash  

Sitemap

Top 主站蜘蛛池模板: 色婷婷亚洲婷婷六月中文字幕 | 久久视频这里只精品re8久 | 国产成人免费av片在线观看婷婷 | 麻豆一区二区免费播放网站 | 海角精产国品一二三区别 | 国产精品美女流白浆视频 | 日韩一道本高清不卡专区 | av一本无码不卡在线播放 | 国产精品亚洲片在线花蝴蝶 | 久久精品动漫一区二区三区 | 国产精品欧美一区二区三区不 | 韩国激情无码一区二区三区 | 亚州免费一级毛片 | 国产精品无码av在线永久 | 一级一级毛片看看 | 伦理片97影视网 | 亚洲日韩高清无码 | 国产日产欧产美韩系列 | 国产又粗又爽又猛的视频A片 | 国产卡二区三卡乱码 | 久久免费视频精品 | 婷婷丁香五月激情综合站 | 国产熟女亚洲精品明星自拍 | 国产片av片永久免费观看 | 东京一本到熟无码免费视频 | 欧美熟妇另类久久久久久多毛 | 国产老肥熟xxxx | 久久久无码精品亚洲日韩18禁 | 国产成人a区在线观看 | 亚洲日韩精品射精日 | 国产v日本v欧美v一二三四区 | 欧美精品一卡二卡 | 日本一道人妻无码一区在线 | 国产人伦精品一区二区三 | 欧美在无码片一区二区 | 18成禁人视频免费网站 | 国产无码视频一区 | a级片小草好吊人妻精美视频网站 | 国产一区二区三区啪视频 | 99精品久久久久久久免费看蜜月 | 成人日动漫卡一区二区三区动漫 |