24 ms·
What you have in your comment is an email address, where anti-phishing training has hopefully helped users to identify non-authentic or at least suspicious doma
by 0x0000000 3y ago
What you have in your comment is an email address, where anti-phishing training has hopefully helped users to identify non-authentic or at least suspicious domains. We (should) know to look at the part after the "@" in an email.
This trick is a URL, not an email address. It looks like a valid URL, because we are accustomed to checking the hostname for authenticity. But the URL in the post is crafted to look like the hostname is X, when in reality it is Y. With URLs, we usually look for the part between the https:// https://, and the first forward / after that. This malicious URL uses unicode characters that look like forward slashes, but aren't, so it appears to be on a different hostname than it is. I don't think anyone is trained to look for the "@" in a URL, and certainly to non-technical folks it's not all that different than a "#" or a "!", i.e., inconspicuous.
- SAI_Peregrinus 3y agoDoesn't every browser "grey out" everything other than the hostname & TLD these days?
- lazycouchpotato 3y agoThey do, but you're probably not doing to come across that when clicking on a URL ending with .zip that downloads a zip file, as shown in the example.
- SAI_Peregrinus 3y agoYou're not likely to see the URL when clicking on it, because the vast majority of sites use links with text other than the URL. Chrome (the most popular browser) truncates the URL that shows up when you hover over it, if you even notice that bar pop up. So they can just make the URL really long to hide the domain, like many scammers already did.
- tedunangst 3y agoI chose to not add https so it wouldn't link.
- pests 3y agoMy only qualm is that similar slash-shenanigans can already happen and cause the same issue with subdomains. How many regular users are going to know the real tdl of the below link? Two subdomains one containing many fake slashes. paypal.com/long/path/to/my/account/.my-evil-invoices.com/transactions.csv