Security Threat From International Domain Names

WASHINGTON, DC – Website owners have a new security threat to worry about in the form of malicious websites spoofing the web addresses of other, unsuspecting, established websites, through the use of international domain names as a way to garner sales through brand confusion.

A variation of the "homograph attack" which exploits weaknesses in the methods that certain web browsers display domain names using non-English characters. This new threat is used by malicious hackers and criminals bent on identity-theft by luring unsuspecting surfers into divulging their personally identifying, and other sensitive information.

The attacks are carried out in a way that exploits character resemblance. For instance, the number "0" and the letter "O" are similar enough to fool unwary users into believing that a fraudulent site is actually the website the surfer was trying to reach.

The exploit takes advantage of new policies from the Internet Engineering Task Force and other concerned groups that support domain names registered in certain national alphabets that use non-English characters. This Internationalized Domain Name (IDN) program enables many non-English speakers to more easily use the Internet, but does so at the expense of creating such opportunities for hackers to carry out these malicious attacks.

Declaring the vulnerability "moderately critical," Copenhagen-based Secunia warned users of the affected browsers about the new threat following a demonstration of this most recent style of homograph attack at hacker convention ShmooCon, held recently in Washington.

According to the The Shmoo Group, browsers such as Firefox 1.0, Apple's Safari Version 1.2.5, and Opera's Version 7.54, are all susceptible to the IDN homograph form of attack, however, Microsoft's Internet Explorer browser isn't thought vulnerable, despite its popularity as a target for attacks.

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Teasy Agency Launches Marketing Firm

Teasy Agency has officially launched Teasy Marketing firm.

Ofcom Investigates More Sites in Wake of AV Traffic Shifts

U.K. media regulator Ofcom has launched investigations into 20 more adult sites as part of its age assurance enforcement program under the Online Safety Act.

MintStars Launches Debit Card for Creators

MintStars has launched its MintStars Creator Card, powered by Payy.

xHamster Settles Texas AV Lawsuit, Pays $120,000

Hammy Media, parent company of xHamster, has settled a lawsuit brought by the state of Texas over alleged noncompliance with the state’s age verification law, agreeing to pay a $120,000 penalty.

RevealMe Joins Pineapple Support as Partner-Level Sponsor

RevealMe has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

OnlyFans Institutes Criminal Background Checks for US Creators

OnlyFans will screen creators in the United States for criminal convictions, CEO Keily Blair has announced in a post on LinkedIn.

Pineapple Support to Host 'Healthier Relationships' Support Group

Pineapple Support is hosting a free online support group on enhancing connection and personal growth.

Strike 3 Rejects Meta 'Personal Use' Defense in AI Suit

Vixen Media Group owner Strike 3 Holdings this week responded to Facebook parent company Meta’s motion to dismiss Strike 3’s suit accusing Meta of pirating VMG content to train its artificial intelligence models.

Pornhub, Stripchat: VLOP Designation Based on Flawed Data

In separate cases, attorneys for Pornhub and Stripchat this week told the EU’s General Court that the European Commission relied on unreliable data when it classified the sites as “very large online platforms” (VLOPs) under the EU’s Digital Services Act, news organization MLex reports.

New Age Verification Service 'AgeWallet' Launches

Tech company Brady Mills Agency has officially launched its subscription-based age verification solution, AgeWallet.

Show More