• Articles
    • Editorial Articles
    • Research Articles
    • WatchGuard Articles
  • The 443 Podcast
  • Threat Landscape
  • About
    • About Us
    • Contact Us
    • Contribute to Secplicity

Secplicity - Security Simplified

Powered by WatchGuard Technologies

Punycode Phishing – Daily Security Byte

April 18, 2017 By Corey Nachreiner

Punycode is one of the ways to represent the Unicode character set using limited ASCII characters, and Unicode is an extended character set used to represent many other types of non-alpha numeric characters. Unfortunately, a Chinese researcher found vulnerabilities in the way Chrome and Firefox handle punycode that could allow attackers to create some pretty legitimate looking domain names for their phishing attacks. Watch today’s video to learn more about this new technique and how it helps phishers.

Episode Runtime: 2:42

Direct YouTube Link: https://www.youtube.com/watch?v=6Wr5zFNyAEU

EPISODE REFERENCES:

  • PunyCode Phishing vulnerability can fool even savvy users – gHacks
  • New Chrome extension alerts on PunyCode – Google
  • Google promises to patch Chrome phishing flaw – Engadget

Corey Nachreiner, CISSP (@SecAdept)

Share This:

Related

Filed Under: Security Bytes Tagged With: Web Attacks

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

The 443 Podcast

A weekly podcast featuring the leading white-hat hackers and security researchers. Listen Now
the 443 podcast

Threat Landscape

Filter and view Firebox Feed data by type of attack, region, country, and date range. View Now
threat landscape

Top Posts

  • US National Cybersecurity Strategy
  • Cybersecurity’s Toll on Mental Health
  • Cybersecurity News: Free Cybersecurity Training, TrickBot Group Exposed, Major GoDaddy Breach, and Russia to Legalize cybercrime?!
  • Here Come The Regulations

Email Newsletter

Sign up to get the latest security news and threat analysis delivered straight to your inbox

By signing up you agree to our Privacy Policy.


The views and opinions expressed on this website are those of the authors and do not necessarily reflect the policy or position of WatchGuard Technologies.

Stay in Touch

Recent Posts

  • Here Come The Regulations
  • US National Cybersecurity Strategy
  • Cybersecurity News: Free Cybersecurity Training, TrickBot Group Exposed, Major GoDaddy Breach, and Russia to Legalize cybercrime?!
  • Cybersecurity’s Toll on Mental Health
  • Successfully Prosecuting a Russian Hacker
View All

Search

Archives

Copyright © 2023 WatchGuard Technologies · Cookie Policy · Privacy Policy · Terms of Use