Earlier quoted context omitted.
The TLD registries are supposed to each have defined rules for IDN which can prohibit abuses and to police the use of your service. If you operate the registry for say, Switzerland, it makes sense to allow what Swiss and maybe German people would want, then forbid everything else. But if you operate .COM or .INFO or .FREE-MONEY or whatever, your goal isn't to help anybody it's to obtain the most money possible withou…
Ah, that is interesting, thank you.
Google-hosted malvertising leads to fake Keepass site that looks genuine
71–80 of 197 posts
Re: Google-hosted malvertising leads to fake Keepass site that looks genuine
#72Earlier quoted context omitted.
I just tried it and… it redirects me to the actual page https://keepass.info/ That is weird. I don’t have mobile debugging set up, or I’d try and figure out what’s going on there.
Right now, using curl, [ķ]eepass.info redirects to xn--eepass-vbb.info and consequently that redirects to official domain keepass.info.
Re: Google-hosted malvertising leads to fake Keepass site that looks genuine
#73The root cause is alphabets/fonts with lookalike characters being permitted in security-critical contexts. Tracing further, it's the mindset that this is a valuable feature, and not a reckless risk, that is to blame. Browser designers should have been feverishly working to further disambiguate Il1O0, not add more risk by allowing a multitude of whole new alphabets!
Maybe restricting those characters to the relevant top level domains? At least you'd notice you're on ķeepass[.]lv
Re: Google-hosted malvertising leads to fake Keepass site that looks genuine
#74Earlier quoted context omitted.
The first "punycode attacks" were using letters that were completely indistinguishable from the "real" ones (e.g. by using Cyrillic letters). I guess the assumption is that the user would be able to identify any letters with diacritics (even if they're indistinguishable from specks of dust on your screen) and avoid them - after all, you wouldn't go to "göogle.com" either?
weird because the keepass example, on chrome + android, looks exactly like a regular k in the address bar.
Because there's a quick 302 redirect from "ķeepass.info" to "keepass.info" :
Chrome F12 Dev Tools network trace: https://imgur.com/a/vrxjsUV
Whether that redirect was there at the time of the Arstechnica article, I don't know.
EDIT ADD: around 12:57 UTC, the 302 redirect was changed to a Youtube video: https://imgur.com/a/TtLxafP
(Somebody is apparently having fun trolling the internet.)
ICANN lookup trivia says "ķeepass.info" domain was created 3 days ago:
Domain Information
Name: xn--eepass-vbb.info
Internationalized Domain Name: ķeepass.info
Registry Domain ID: a375f89abb384328a10460509f9f99f8-DONUTS
Domain Status:
clientTransferProhibited
addPeriod
Nameservers:
leia.ns.cloudflare.com
sevki.ns.cloudflare.com
Dates
Registry Expiration: 2024-10-16 10:21:45 UTC
Updated: 2023-10-19 11:40:19 UTC
Created: 2023-10-16 10:21:45 UTCRe: Google-hosted malvertising leads to fake Keepass site that looks genuine
#75That, and them showing war videos in ads to little kids.
Re: Google-hosted malvertising leads to fake Keepass site that looks genuine
#76Re: Google-hosted malvertising leads to fake Keepass site that looks genuine
#771) Use an ad blocker, always. 2) In advertisements, Google shouldn't allow the advertiser to modify the domain that is displayed. Really, why do they even do this? 3) IDN shouldn't be enabled by default.
> 2) In advertisements, Google shouldn't allow the advertiser to modify the domain that is displayed. Really, why do they even do this? Because advertisers usually want to send links to a tracker site of their own first so that they can verify if their numbers match up with what Google reports. No one trusts anyone in the advertising space, and for good reasons. Advertising has always been a space filled to the brim…
See previously, gilimp and https://fxtwitter.com/ericlaw/status/1712531148356661494.
Re: Google-hosted malvertising leads to fake Keepass site that looks genuine
#78The root cause is alphabets/fonts with lookalike characters being permitted in security-critical contexts. Tracing further, it's the mindset that this is a valuable feature, and not a reckless risk, that is to blame. Browser designers should have been feverishly working to further disambiguate Il1O0, not add more risk by allowing a multitude of whole new alphabets!
Character substitutions like ķeepass or ƙeepass or keypass are at least possible to spot if you know the name of the product, but not the full URL.
But there are many ways to create lookalike domains that don't change the product name: https://keepass.org https://keepass.net https://keepass.info https://keepass.cx https://keepassxc.org https://keepass-info.net https://keepass-manager.com
Which of these is the correct one? (It's https://keepassxc.org of course, but just looking at the URL won't tell you that.)
The root cause is downloading software you see advertised on Google even though that does not in any way establish trustworthiness.
Re: Google-hosted malvertising leads to fake Keepass site that looks genuine
#79Earlier quoted context omitted.
It's not xenophobic, it's just realistic. If you tried to run a fake, malware-laden website in a Western country you would eventually be shut down and prosecuted. These scams mostly fester in nations with weaker institutions, not just Eastern Europe but also China and India. Their authorities are simply not interested in preventing this kind of unlawful activity.
Can you somehow quantify it or is it your gut feeling? Any articles out there? I don't know if they catch small fish as in this example, it just isn't in the news. The bigger fish happens to be in the news, like shutting down international scam call center - 2 in LV, 1 in LT. Video from police cam if anyone wants to see smashing windows: https://www.vp.gov.lv/lv/jaunums/verieniga-starptautiska-ope... We are also bein…
https://krebsonsecurity.com/2021/05/try-this-one-weird-trick...
> In Russia, for example, authorities there generally will not initiate a cybercrime investigation against one of their own unless a company or individual within the country’s borders files an official complaint as a victim.
Re: Google-hosted malvertising leads to fake Keepass site that looks genuine
#80It ought to be possible to click on the corner of an ad and get the company number and business address of those responsible for it. "Overseas" adverts originating in different countries should be even more heavily checked, because if they're fraudulent then recourse is much harder even if they're not anonymous.