5 ms·
> that clearly listed the destination URL as homedepot.com Does anyone have an explanation for this? I've heard such claims before, but I'd like to see it to
by foxfluff 5y ago
> that clearly listed the destination URL as homedepot.com
Does anyone have an explanation for this? I've heard such claims before, but I'd like to see it to believe it. I could perhaps imagine yet another unicode "feature" (non-printing characters or some very subtle combining characters or a font variant?) being abused for this. On the other hand, part of me wants to believe that despite all their failings, there's no way Google wouldn't have thought of that and prevented it. Right?
EDIT: Somewhat recently I tried to find out if this is true after someone claimed they had had a legit URL lead them to a phishing site, but the only juice I found is the same old: typo-squatting. Just now showing up in big G's results. Apparently e.g. homedopet.com leads to a site that uBlock doesn't want me to visit (badware risks). On the other hand homedepet.com and homodepot.com took me to the right site.
- sliken 5y agoI'm pretty security conscious, and I immediately double checked and replicated what I had done. The ad looked perfect, including the right URL, and includes the normal subsections, store finder, special of the day, careers, etc. The home depot search result labeled as an "ad", but shown inline, with an easy to miss small gray font mentioning the URL. Much like if you search for ace hardware now, I did notice that home depot searches no longer shows an ad. I normally have zero plugins enabled, but I did discover I had a keybase plugin installed, from before zoom bought them. I've since disabled it and am considering a reinstall. The URL it sent me to was: http://34.220.130.1/window-security-alert/werrx01/ http://34.220.130.1/window-security-alert/werrx01/, which at the time worked (visit at your own risk). But I tried it just now and it now triggered a chrome warning about "Deceptive site ahead".
- easrng 5y agoIIRC you can set the domain you want to show on your ad and it doesn't have to be what you actually link to. They allow that so marketers can do click tracking stuff I guess.
- foxfluff 5y agoSad if true. Outright irresponsible, I would say. Knowing which domain you're talking to is such a basic security requirement; TLS and the whole CA model is worth nothing if you're being lied about what domain you're navigating to. This is also why typosquatting is such a dangerous attack..