4 ms·
Here's the original source by the author: https://scribe.rip/@bobbyrsec/the-dangers-of-googles-zip-tld-5e1e675e59a5 https://scribe.rip/@bobbyrsec/the-dangers-of
by watashiato 3y ago
Here's the original source by the author: https://scribe.rip/@bobbyrsec/the-dangers-of-googles-zip-tld-5e1e675e59a5 https://scribe.rip/@bobbyrsec/the-dangers-of-googles-zip-tld...
While I think that we really don't need a .zip domain, this trick falls apart when not shown as an image. Hovering over either URL should tip you off. Firefox shows the actual link in the bottom left.
- DerekL 3y agoHow exactly does this trick work? Thing is, a URL can't have any non-ASCII characters in it. So this would only happen if the webpage or some app takes the URL and undoes the percent-encoding to try to make it more readable.
- DerekL 3y agoI just tried the fake URL by pasting it into Safari's address bar, and it “helpfully” percent-encoded the special slashes and tried to go to v1271.zip.
- CydeWeys 3y agoThis so-called attack is also not as effective in most contexts as the simple <a href="https://evilsite.com">https://goodsite.com</a> https://evilsite.com">https://goodsite.com</a> trick. Raw URLs in web pages don't get auto-linkified anyway, so something is turning it into a link (e.g. through use of HTML), and at that point you can have the link text and the URL be whatever you want, completely independently of each other.
- donmcronald 3y ago> Hovering over either URL should tip you off. Firefox shows the actual link in the bottom left. Most people don't even know what a URL is, let alone how to discover this kind of deception by looking at the hover info.
- mid-kid 3y agoat that point you can just use a regular hyperlink without showing the url on the page at all.