Article 78Z2J Two characters open up a world of typosquatting opportunities in Chromium browsers

Two characters open up a world of typosquatting opportunities in Chromium browsers

by
from www.theregister.com - Articles on (#78Z2J)
Story ImageResearchers say two characters available to typosquatters and phisherfolk can trick Chromium browsers into displaying lookalike URLs as genuine web addresses. Wangling a domain name to look an awful lot like that of a popular website is nothing new. We've all encountered phishing sites such as macrosoft[.]com and applle[.]com before in our daily struggles against spam. However, as browsers mature, new characters are always being made available for use. This opens up new opportunities for those whose languages contain characters/homoglyphs that aren't ASCII-compliant, but it also introduces new ways for attackers to abuse display logic quirks in programs like Chrome and Edge. According to Ian Muscat and Leanne Briffa of Have I Been Squatted, there are still characters available to cyber-imposters that can reliably fool web users into trusting URLs that they certainly should not. The latest glyphs bypassing browser safety checks allow tricksters to run websites from a clearly fake domain name (when displayed in Punycode), although they appear just like the real deal in Unicode. The characters of note, in this case, are , which is found in various Cyrillic languages such as Kazakh, Mongolian, and Tatar, and the Latin K with hook, , used in Hausa and Karai-karai. Both are visually similar to the letters e/o, i, and k, respectively, and allowed the researchers to register 20 lookalike domain names. These included: a[.]com s[.]com ota[.]com nie[.]com Below are the URLs' Punycode equivalents - how browsers should display them safely: xn--80a6aa68c8d.com xn--80a5aeq0fr0c.com xn--ota-f6a.com xn--nie-g6a.com You can try them out; they're registered by Have I Been Squatted and are safe to visit. They take you to research demo pages set up by the researchers, and each page explains how exactly they bypass browser protections. Crucially, they all bypass the key security measures deployed by Chromium-based browsers. How the bypasses work Browsers deploy two main defense layers. The first is a set of seven sequential checks run by Chromium's SafeToDisplayAsUnicode function, which check for a range of common spoofing methods. Vendors began introducing these checks in 2017 after researcher Xudong Zheng registered .com - a domain consisting of all-Cyrillic characters. Chromium's checks, which factor in a hardcoded list of known Cyrillic characters known to be used in place of Latin letters, can be seen as "all or nothing." Built to detect all-Cyrillic strings, the measure only takes action against domain names if every character in the string is on its hardcoded list. If one character is missing, the check is bypassed. Characters such as , , and , are known as breakers," as these are not present in the lookalike list, as of Chrome 154 (released to stable channel on September 22). Failing any of the seven display checks tells the browser that the characters are unsafe to display as Unicode and to instead display the Punycode, revealing just how dissimilar they are to the genuine domains they try to imitate. The second measure browsers take is to compare the domain name against a list of popular websites to see if it is trying to imitate one of them. In Chromium, these checks are handled by the GetSimilarTopDomain() function. This step converts a supplied domain name into a "skeleton," stripping its characters of diacritics, such as accents (o becomes o), and checking the skeleton URL against a hardcoded list of popular websites. Chromium checks against almost 8,500, and if the skeleton matches any of them, then it displays Punycode. However, the Latin K with hook, , does not have an accent, and is added to the skeleton as a Latin k with an added combining mark, bypassing the security check. In this case, the skeleton is formed as: [o k t a . c o r n]. (The skeleton maps "m" to "rn"). Likewise, with .com, the Cyrillic barred o retains its bar in the skeleton as a combining mark, meaning it does not match the genuine Apple domain. Its skeleton is formed as: [a p p l o - . c o r n]. Browsers are always working to stymie these tools of imposterment. Chrome 148 put an end to attackers being able to use and as breakers to imitate their Latin lookalikes, for example. The two main security checks are not the only lines of defense. Chromium also deploys warnings at the time of navigation called Safety Tips. An example domain that would bypass the two main checks is instagarm[.]com. The inflection on the beginning character is removed and what's left is essentially the real Instagram domain with two letters swapped. The Instagarm domain does not match any of the hardcoded sites, nor does it contain any banned characters. In this case, Chrome will display one of two popups, asking the user if they meant to visit the genuine domain, warning that the current direction of travel appears fake. However, there are limits to this extra security layer. The warnings only trigger when an imitation domain is an exact-character match, a one-edit match, or a match with an adjacent swap from the genuine URL. Two or more changes, like with [.]com, which has all-Cyrillic characters preceding the ".com," will not trigger these warnings. The warnings will also not trigger with domains consisting of fewer than five characters. Domains such as ota.com, which is only one edit from the real Okta, may not trigger defenses because of the one-edit rule and the fact that it is only four characters. Safety Tips also checks the skeleton against the sites users visit regularly, not just the hardcoded list of trusted sites. Frequently visited sites may trigger the same warnings, but for users who do not have a comprehensive visit history, the defense layer may fail. The defenses described here only apply to browsers. Email clients are even less picky with imitation domain strings. Websites like Gmail displayed each of the 20 domains HIBS fed the clients, which were a mix of lookalikes and genuine internationalized domain names (IDNs), as an attacker would want it to, all in Unicode. Outlook Web showed all 20 as Punycode, even the harmless ones, suggesting neither apply the right checks to properly inform users. To quantify the scale of the issue, the researchers looked at ICANN's list of every .com domain. There are around 167 million of them, approximately 733,000 of which are IDNs, those that contain non-ASCII characters and are stored in Punycode form. The researchers took each of the IDNs and swapped their non-ASCII characters for ASCII equivalents to determine how many matches there were. They found around 162,000 pairs - IDNs that resemble plain ASCII domains. It should be said that this does not mean there are circa 162,000 typosquatted domains, just that many yield lookalikes. Some may be registered by businesses for defensive purposes; others may be owned by the same business that wants to operate multiple websites catering to different languages. However, organizations should be aware of the means available to typosquatters, and monitor registered domains accordingly. (R)
External Content
Source RSS or Atom Feed
Feed Location http://www.theregister.co.uk/headlines.atom
Feed Title www.theregister.com - Articles
Feed Link https://www.theregister.com/
Reply 0 comments