Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

Hack5190

macrumors 6502a
Original poster
Oct 21, 2015
531
311
(UTC-05:00) Cuba
The way browsers display Punycode (support for foreign characters) has been a potential for abuse since it was implemented. However as Phishing attacks increase, the use of Punycode as a way to fool users has surfaced.

Punycode allows someone to register domain with foreign characters that will be displayed using only ASCII characters. For example, this page

daea1fdcd6a324778f3274a64b6dfc24e6073874067835efefe5e26870baa383.png


is actually

a502b06561524ec740ec6e8cb11fbd931f6fb219f42a0be6de275f97d44a514a.png


(check out the demo web page)

The workaround is to make FireFox & TenFoxFour display Punycode instead of using only ASCII characters. Here are the needed steps to make the change:

  1. Type about:config in address bar and press enter.
  2. Type Punycode in the search bar.
  3. Browser settings will show parameter titled: network.IDN_show_punycode, double-click or right-click and select Toggle to change the value from false to True.
 

eyoungren

macrumors Penryn
Aug 31, 2011
28,792
26,879
The way browsers display Punycode (support for foreign characters) has been a potential for abuse since it was implemented. However as Phishing attacks increase, the use of Punycode as a way to fool users has surfaced.

Punycode allows someone to register domain with foreign characters that will be displayed using only ASCII characters. For example, this page

daea1fdcd6a324778f3274a64b6dfc24e6073874067835efefe5e26870baa383.png


is actually

a502b06561524ec740ec6e8cb11fbd931f6fb219f42a0be6de275f97d44a514a.png


(check out the demo web page)

The workaround is to make FireFox & TenFoxFour display Punycode instead of using only ASCII characters. Here are the needed steps to make the change:

  1. Type about:config in address bar and press enter.
  2. Type Punycode in the search bar.
  3. Browser settings will show parameter titled: network.IDN_show_punycode, double-click or right-click and select Toggle to change the value from false to True.
Thank you Hack! I've made this change!
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.