Live data from Hacker News

Attackers Used Look-Alike Domains to Steal $1M from a Chinese VC

darkreading.com

21–30 of 37 posts

Re: Attackers Used Look-Alike Domains to Steal $1M from a Chinese VC

#21

How are these cases usually handled in court? Could the Chinese VC possibly require the startup to pay damages over insufficient security measures?

Potentially but then that would probably mean their deal is off. ..not sure they want that.

Re: Attackers Used Look-Alike Domains to Steal $1M from a Chinese VC

#22
post #14

Firefox users: be sure to set "network.IDN_show_punycode" to "true" in about:config. Test with the fake Apple domain https://www.xn--80ak6aa92e.com/ . See "Phishing with Unicode Domains" for more information: https://www.xudongz.com/blog/2017/idn-phishing/ .

The other day I was browsing a list of all my country's domains and noticed a bunch starting with xn-- and you just made me understand what these are.

None of them seem worth phishing for. In some cases when you google the site name, google will show results from sitename.tld and when you visit the site with the show_punycode true, it will actually load pages from the xn-- equivalent. So it looks like the "original" domain isn't even indexed or online at all.

In another case both the xn-- and "normal" domain sit side by side on the same server. I guess there's no harm in posting these:

cadzandie.be and xn--cadzandi-01a.be. Note there's no ë in the first domain

Another strange one is

xn--rembours-i1a.be

When you type in remboursé.be it actually redirects (?) to the xn-- equivalent.

I'm fascinated but having a hard time seeing sense in this.

Re: Attackers Used Look-Alike Domains to Steal $1M from a Chinese VC

#23
post #19
post #14

Firefox users: be sure to set "network.IDN_show_punycode" to "true" in about:config. Test with the fake Apple domain https://www.xn--80ak6aa92e.com/ . See "Phishing with Unicode Domains" for more information: https://www.xudongz.com/blog/2017/idn-phishing/ .

For the situation in the article it would not have changed anything. As the fake domains were just adding an 's' to the end of the domain. Also I'm not sure what effect that will have for Chinese users. It might make many of their URLs look strange to them. See: https://www.reddit.com/r/firefox/comments/7ul9p3/why_is_netw...

I'm not aware of any Chinese websites that don't just use Pinyin for their domain name. Some random person is squatting on http://xn--wxtr44c.xn--fiqs8s/ (百度.中国), but Baidu doesn't seem to care. They use http://www.baidu.com/ as their primary address.

Re: Attackers Used Look-Alike Domains to Steal $1M from a Chinese VC

#26
post #23
post #19

Earlier quoted context omitted.

For the situation in the article it would not have changed anything. As the fake domains were just adding an 's' to the end of the domain. Also I'm not sure what effect that will have for Chinese users. It might make many of their URLs look strange to them. See: https://www.reddit.com/r/firefox/comments/7ul9p3/why_is_netw...

I'm not aware of any Chinese websites that don't just use Pinyin for their domain name. Some random person is squatting on http://xn--wxtr44c.xn--fiqs8s/ (百度.中国), but Baidu doesn't seem to care. They use http://www.baidu.com/ as their primary address.

> I'm not aware of any Chinese websites that don't just use Pinyin for their domain name.

There are tons. One prominent email provider is a three-digit number. There's a job board at 51job.com.

(What's 51job? Read in Mandarin, that would be "wǔ yāo job" [five one "job" (the English word)]. This is felt to sound similar to "wǒ yào job" 我要job [I want a job].)

Re: Attackers Used Look-Alike Domains to Steal $1M from a Chinese VC

#27

“Such scams .. show why secondary protection mechanisms — like verbal confirmation — are necessary when making high-value transactions” How about digital signatures and end-to-end email encryption.

Encryption only verifies it hasn't been changed or viewed by a third party, the original email contained the problem so you would just store an encrypted string that would decrypt with the attack in it

Re: Attackers Used Look-Alike Domains to Steal $1M from a Chinese VC

#28
post #3
post #2

I heard this story from a local startup as well - an investor ended up losing ~$100k because the investor's email account was compromised and a lookalike domain was used to impersonate the startup. I've been calling people out-of-band for verification using phone numbers from past communications, even if I'm working on transactions that don't seem out of the ordinary. Not that SIM card fraud doesn't happen, but at le…

Isn’t it time to see more widespread use of encryption in emails? What I’m pertaining to is signing emails to make sure they are coming from correct source.

As bayarrhea points out, a signature doesn't help you if the attack model is "lookalike domain".

Email validation exists; gmail will let you know if email arrived over TLS or not. Validation that the source of an email matches the "From:" header is generally done by checking the domain's SPF record.

https://en.wikipedia.org/wiki/Sender_Policy_Framework

https://en.wikipedia.org/wiki/Email_spoofing#Countermeasures

Re: Attackers Used Look-Alike Domains to Steal $1M from a Chinese VC

#29
post #14

Firefox users: be sure to set "network.IDN_show_punycode" to "true" in about:config. Test with the fake Apple domain https://www.xn--80ak6aa92e.com/ . See "Phishing with Unicode Domains" for more information: https://www.xudongz.com/blog/2017/idn-phishing/ .

It is beyond unacceptable that this bug is 3 years in the wild.

Real people have been owned by this idiotic response from mozilla.

I’ve used Firefox since it was actually called “Mozilla”.

I’ve never been more upset at a decision of theirs than now.

Post reply on HN