How do The Naughty New Mom Is My First Love Teacher (2025)you spot a phishing scam when the URL looks perfectly legit?
An old phishing technique has recently popped back up in the news, and it has the potential to fool some folks no matter how many times they inspect a URL for typos.
SEE ALSO: Your internet data is absolutely a national security issuePhishing works like this: Some fool sends people an email that asks readers to please click on this link or download this thing. The person sends the link from a URL with a (theoretically) clever typo (think yhaoo.com instead of yahoo.com). But this other kind of phishing scheme -- called a homograph attack -- sends an email from a URL that looks nearly identical to the real thing, replacing some the letters with similar ones from other alphabets.
Look at this example of the real apple.com and an imposter created by web developer Xudong Zheng, who brought renewed attention to homograph attacks by writing about them on April 14.
A homograph attack replaces all the letters in a URL with similar or identical letters from non-English alphabets such as Cyrillic.
Here's how it works: Zheng's fake "apple.com" is actually a translation. Its true URL looks like this: "xn--80ak6aa92e.com."
That keyboard vomit means nothing to me, but this arrangement of letters and dashes and numbers corresponds to Cyrillic letters. It's written in unicode, a coding standard that pulls from a wide range of letters and numbers and whatever else. But, with the help of a separate tool called punycode, that illegible URL is translated into something called American Standard Code for Information Interchange, which renders URLs in English. Thus, that unreadable mess becomes a fake apple.com.
This is an issue for anyone using Firefox, Chrome and several less popular browsers, though not for folks using Safari or Internet Explorer. But while the regular URLs are seemingly impossible to distinguish from the bad ones, the fix is still relatively simple (if kind of annoying).
If you get an email you're not sure about, and it asks you to click on a link, don't. Instead, Zheng suggests, type it out into a browser or a search engine. This will take you to the legitimate link, if there is such a thing. A few seconds of extra key-tapping could save you a whole lot of malware issues.
Another bit of good news: Zheng says homograph attacks aren't all that common because once a Cyrillic-based URL is blacklisted, it's pretty much useless. Homograph attacks only work if each letter of the real URL is replaced with a letter from a different alphabet. If a Cyrillic-based site gets blacklisted, the phisher can't just come back with a different fake arrangement of letters and try again.
In less good news, Zheng says homograph attacks often aren't necessary. Phishers trick plenty of people with schemes that aren't so complex.
(Editor: {typename type="name"/})
Inter Milan vs. Urawa Red Diamonds 2025 livestream: Watch Club World Cup for free
Iguana, who answers to no man, wreaks havoc at the Miami Open tennis tournament
This game is teaching particle physics to five
Cost Per Frame Analysis: The Best Graphics Cards in Mid 2025
Denmark vs. France 2025 livestream: Watch U21 Euro 2025 for free
Millennials can't shut up about sex, blame the internet
A whole state in India is giving all college students free internet access
It's time to start thinking about cybersecurity for sharks. Yes, the fish.
Android 16: These 6 features are worth the update
Memes don't just look good on the internet, they also look good on your eyelids
Mikey Angelo's 3 essential tools for creating viral content
Drake's new album has inspired a whole lot of Google searches
接受PR>=1、BR>=1,流量相当,内容相关类链接。