Security Threat From International Domain Names

WASHINGTON, DC – Website owners have a new security threat to worry about in the form of malicious websites spoofing the web addresses of other, unsuspecting, established websites, through the use of international domain names as a way to garner sales through brand confusion.

A variation of the "homograph attack" which exploits weaknesses in the methods that certain web browsers display domain names using non-English characters. This new threat is used by malicious hackers and criminals bent on identity-theft by luring unsuspecting surfers into divulging their personally identifying, and other sensitive information.

The attacks are carried out in a way that exploits character resemblance. For instance, the number "0" and the letter "O" are similar enough to fool unwary users into believing that a fraudulent site is actually the website the surfer was trying to reach.

The exploit takes advantage of new policies from the Internet Engineering Task Force and other concerned groups that support domain names registered in certain national alphabets that use non-English characters. This Internationalized Domain Name (IDN) program enables many non-English speakers to more easily use the Internet, but does so at the expense of creating such opportunities for hackers to carry out these malicious attacks.

Declaring the vulnerability "moderately critical," Copenhagen-based Secunia warned users of the affected browsers about the new threat following a demonstration of this most recent style of homograph attack at hacker convention ShmooCon, held recently in Washington.

According to the The Shmoo Group, browsers such as Firefox 1.0, Apple's Safari Version 1.2.5, and Opera's Version 7.54, are all susceptible to the IDN homograph form of attack, however, Microsoft's Internet Explorer browser isn't thought vulnerable, despite its popularity as a target for attacks.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Fast-Tracked Arizona Bill Includes Consent 'Catch-22' for Adult Sites

A bill advancing rapidly through the Arizona state legislature would impose new requirements for adult content uploaded online, including seemingly contradictory provisions that could effectively make it impossible for adult sites to operate in the state.

VirtualRealPorn Launches New WebXR Site

VirtualRealPorn has officially launched its new site, powered by Web Extended Reality (WebXR).

'MyAsianGFs' Launches Through Paysite.com

MyAsianGFs.com has officially launched through Paysite.com.

Corey Silverstein to Host Webinar on North Carolina Age Verification Thursday

Adult industry attorney Corey D. Silverstein has announced his latest "Legal Impact" webinar, titled "North Carolina AV Law — Content Creation Issues," to livestream Thursday at 4 p.m. (EST).

Ofcom Fines 8579 LLC $1.8 Million for AV Noncompliance

U.K. media regulator Ofcom on Monday imposed a fine of 1.35 million pounds (more than $1.8 million) against adult site operator 8579 LLC for failing to implement age checks as required for compliance with the Online Safety Act.

Pearl Industry Network Launches 'TrustLink' Creator Verification Platform

Trade group Pearl Industry Network (PiN) has launched TrustLink, its free creator verification platform.

FSC Updates Complaint in Tennessee AV Case, AG Motions to Dismiss

The Free Speech Coalition this week filed an amended complaint in its lawsuit challenging the Protect Tennessee Minors Act as unconstitutional, in response to which the Tennessee attorney general motioned for dismissal of the case.

Cherie DeVille Joins Woodhull Freedom Foundation 'Free Speech' Panel

Multi-XMAs winner Cherie DeVille will join the upcoming Woodhull Freedom Foundation panel series "Fact Checked by Woodhull," addressing free speech on Feb. 26.

Wisconsin AV Bill Moves Ahead, Minus Anti-VPN Provisions

The Wisconsin state Senate on Wednesday advanced a bill that would require adult websites to verify the ages of users, but approved an amendment striking proposed language that would have required sites to block virtual private network traffic.

Pineapple Support Introduces 'Wellbeing by PS' Service

Pineapple Support has debuted its new Wellbeing by PS service, providing mental health support packages for companies and agencies.

Show More