Closed
Bug 1627849
Opened 6 years ago
Closed 6 years ago
URL Spoofing using “◌̣” (U+0323)
Categories
(Firefox :: Address Bar, defect)
Tracking
()
RESOLVED
DUPLICATE
of bug 1405845
People
(Reporter: rayyanh12, Unassigned)
Details
(Keywords: reporter-external)
Attachments
(1 file)
|
34.94 KB,
image/png
|
Details |
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.163 Safari/537.36
Steps to reproduce:
http://www.xn--google-e4d.com/
By adding this * ̣ * (notice the DOT under asterisk) we can actually spoof the URL (espicially the inexperienced users)
Actual results:
Expected results:
The URL should be shown in PunnyCode
Comment 1•6 years ago
|
||
This is a variation of the problem in bug 1405845. To the extent registrars are letting these through (are they really?) the best solution is represented by bug 1507582 (see the example URL in that bug: airfrance with a dot under one of the characters).
Status: UNCONFIRMED → RESOLVED
Closed: 6 years ago
Component: Untriaged → Address Bar
Resolution: --- → DUPLICATE
Updated•6 years ago
|
Group: firefox-core-security
Updated•6 years ago
|
Flags: sec-bounty-
Updated•2 years ago
|
Keywords: reporter-external
You need to log in
before you can comment on or make changes to this bug.
Description
•