For Apple users without latest security updates, the letter 'd' is not always the letter 'd'

Science & Tech 14:09 20.11.2018

Most Apple users install updates, but there's always a small group of people who, for various reasons, lag behind when it comes to installing updates, for one reason or another, legitimate, or not.

If you're one of the users in the latter category, then you should be aware that the letter "d" is not always the letter "d" when displayed inside the Safari address bar.

This might sound like a non-issue, but it's actually a very important problem that all Apple users who don't run the latest OS software need to be aware of, as they could fall victims to what security researchers call "IDN homograph attacks."

IDN homograph attacks happen when someone registers a domain using Unicode characters that look like standard Latin letters, but they are not. For example, coinḃase.com is an IDM homograph attack for coinbase.com (notice the dot above the letter b).

These lookalike domains are usually used for phishing, tricking users into thinking they accessed a legitimate site when they're on a cleverly crafted clone.

IDN homograph attacks have been an issue over the past year, and several incidents have been reported in the security news media about homograph attacks against cryptocurrency exchanges in 2017 and 2018.

Driven by this new wave of homograph attacks, xisigr, a security researcher at Tencent Security Xuanwu Lab, has recently taken a look at how Apple products handle Unicode characters.

What the researcher found is that Apple does a good job with most Unicode characters, except one --which is the letter dum (ꝱ) (U+A771), part of the extended Latin alphabet character set.

The letter looks like a normal Latin lowercase letter 'd', except it comes with a lower apostrophe. But xisigr found that Safari did not render the small lower apostrophe, displaying the letter dum as a Latin letter d.

apple-letter-d-dum.png

The Tencent researcher reported his findings to Apple, who issued security updates in July for Safari, iOS, macOS, tvOS, and watchOS.

Unfortunately, users who have not applied those updates are still vulnerable to phishing attacks. An attacker can record domain names that include the letter dum and he can launch phishing campaigns against Apple users.

Xisigr says the issue should not be ignored because he found that the letter d is part of almost 25 percent of all Top 10,000 domains, providing attackers with a huge phishing surface.

Some of the domains that a phisher could impersonate include LinkedIn, Baidu, Dropbox, Adobe, WordPress, Reddit, or GoDaddy, just to name a few.

Furthermore, even if some domain registrars prevent users from registering domain names that contain Unicode characters, this limitation doesn't apply to the letter dum because it's part of the extended Latin character alphabet, and hence, is considered a standard Latin character.

If Apple users can't update, for the time being, they should at least take notice that the letter "d" in Safari's URL bar may not actually be "d" and they should use another browser to navigate the web until they can apply Apple's July security patches.

How Azerbaijan contributed to victory in WWII? - VIDEO

News line

How Azerbaijan contributed to victory in WWII? - VIDEO
13:54 09.05.2024
A Living Testament to Valor: 99-Year-Old Veteran Recalls Second World War Triumphs - INTERVIEW
13:36 09.05.2024
Baku Honors World War II Veteran : VIDEO
13:12 09.05.2024
Israeli MFA Political Director Honors War Hero Hazi Aslanov in Baku Visit
12:50 09.05.2024
Putin: Russia’s strategic forces always in combat readiness
Putin: Russia’s strategic forces always in combat readiness
12:21 09.05.2024
President Ilham Aliyev grants awards of President of Republic of Azerbaijan to artists - ORDER
12:00 09.05.2024
President Ilham Aliyev and First Lady Mehriban Aliyeva pay tribute to Azerbaijanis who died for Victory over fascism
11:40 09.05.2024
North Macedonia elects first woman president
11:21 09.05.2024
Permanent reps of Azerbaijan, Türkiye to UN mull bilateral relations
11:05 09.05.2024
US Department of Defense inks contract with Lockheed Martin for production of HIMARS MLRS
US Department of Defense inks contract with Lockheed Martin for production of HIMARS MLRS
10:50 09.05.2024
First Vice President of Azerbaijan Mehriban Aliyeva shares a post on occasion of 9 May Victory Day
10:25 09.05.2024
Ambassador: Azerbaijan to host side event focusing on environmental consequences of landmines on margins of COP29
10:16 09.05.2024
Turkish Opposition Leader Özgür Özel Announces Planned Visit to Azerbaijan
10:00 09.05.2024
Number of Palestinians killed in Gaza Strip exceeds 34,800
Number of Palestinians killed in Gaza Strip exceeds 34,800
09:45 09.05.2024
Erdogan: Peace agreement between Baku and Yerevan should be signed as soon as possible
09:35 09.05.2024
President Ilham Aliyev sends a letter of invitation to COP29 to Turkish President Erdogan
09:17 09.05.2024
Presidents of Azerbaijan and Bulgaria make press statements - FULL
09:00 09.05.2024
79 years pass since victory of German fascism
00:00 09.05.2024
Global Forum on Antisemitism: Azerbaijan is truly a safe place for all Jews, Gady Gronich says
Global Forum on Antisemitism: Azerbaijan is truly a safe place for all Jews, Gady Gronich says
22:35 08.05.2024
Armenia suspends financing CSTO
21:00 08.05.2024
Horror movie to be made about Jesus’ childhood
20:02 08.05.2024
Israel's team reportedly to stay for further Cairo talks
Israel's team reportedly to stay for further Cairo talks
19:40 08.05.2024
China, Serbia sign agreement of 'shared future'
19:20 08.05.2024
VDL calls for protection against subsidized Chinese EVs
VDL calls for protection against subsidized Chinese EVs
19:00 08.05.2024
Britain says it will expel Russian defence attache
18:45 08.05.2024
'A major turning point': More than 30% of world’s energy now comes from renewables
18:22 08.05.2024
Boeing cargo plane forced to land at Istanbul without front landing gear - VIDEO
Boeing cargo plane forced to land at Istanbul without front landing gear - VIDEO
18:03 08.05.2024
Did Netanyahu Trash Ceasefire Deal Agreed by Hamas to Continue War? - ANALYSIS
17:49 08.05.2024
Tax Evasion Amid War: Economic Struggles in Ukraine
17:33 08.05.2024
US Ramps Up Search for Alternative to Ukraine's Zelensky - Russian Intel Service
17:19 08.05.2024
Passport System Failure Sparks Chaos at UK Airports
Passport System Failure Sparks Chaos at UK Airports
17:08 08.05.2024
Azerbaijan's Peace Initiative at COP29: Insights from Tofig Abbasov
17:00 08.05.2024
Israel should start peace talks with Hamas - White House Spokesman
Israel should start peace talks with Hamas - White House Spokesman
16:46 08.05.2024
Insights into Pashinyan's Moscow Visit: Expert Analysis
16:27 08.05.2024
President Ilham Aliyev invites his Bulgarian counterpart to COP29
16:00 08.05.2024
Foreign Ministries of Azerbaijan, Israel hold consultations
15:45 08.05.2024
First lady of Bulgaria gets acquainted with dishes of Azerbaijani national cuisine
First lady of Bulgaria gets acquainted with dishes of Azerbaijani national cuisine
15:30 08.05.2024
Russian MFA: Trilateral statement remains relevant
15:17 08.05.2024
Kremlin expert: This will lead to the fact that ties between Armenia and Russia will begin to break down - VIDEO
15:00 08.05.2024
Bloomberg: Russians Are Coming to Terms With Putin’s War in Ukraine
14:27 08.05.2024
Hamısı