Skip to content

Adding 'Domain Name Homograph' into learning resources at Detecting, Investigating and Tracking Malicious Infrastructure #191

@XavCC

Description

@XavCC

I've noticed that there's a case missing that's not very common but has a high potential for harm.
Homograph International Domain Names (IDNs) for phishing purposes.
One example among many possibilities:

exampʟe[.]com (xn--exampe-0dd[.]com)

A message or an email, received with such a homograph brings a great deal of confusion and therefore risk to the person targeted.
Although Internet and software players have put in place a number of mitigating parameters, this is still a common occurrence. And because it is little known, it has a high potential for causing harm.

Before going into the aspects of writing to complete the resources and before the technical and methodological details, I need to know where to put this scenario.
I was thinking of putting it here: …/module-5

But I'm not sure. Perhaps a dedicated file/module needs to be created, or is that too much?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions