TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Google Is Battling a Russian Spammer Over the Use of the Letter 'G'

52 点作者 bloomca超过 8 年前

13 条评论

r1ch超过 8 年前
I think an issue here is Google is showing "ɢoogle" as "ɢoogle.com" and not "xn--oogle-wmc.com". The .com TLD has no support for IDNA2008 so they allow registration of these similar-looking unicode TLDs. This is why if you paste ɢoogle.com in your browser it will show the punycode instead. Basically it looks like Google is decoding punycode for all TLDs, not just those that support IDNA2008.
foepys超过 8 年前
This shows the problems with unicode in domain names. Some Cyrillic characters look exactly like Latin characters but have different codepoints, e.g. a (0x61) and а (0xB0D0). This is pretty important for businesses whose domain include an a, like banks.<p>Google is now noticing that those malicious domains don&#x27;t even have to be an exact visual match but a similar looking one is sufficient to trick users.
评论 #13540199 未加载
评论 #13540917 未加载
评论 #13544273 未加载
评论 #13541503 未加载
morsch超过 8 年前
Accessing the domain in question (ɢoogle.com) redirects to this fairly bizarre chain of subdomains<p><pre><code> http:&#x2F;&#x2F;money.get.away.get.a.good.job.with.more.pay.and.you.are.okay.money.it.is.a.gas.grab.that.cash.with.both.hands.and.make.a.stash.new.car.caviar.four.star.daydream.think.i.ll.buy.me.a.football.team.money.get.back.i.am.alright.jack.ilovevitaly.com&#x2F;</code></pre>
评论 #13540261 未加载
评论 #13540444 未加载
评论 #13540251 未加载
评论 #13540263 未加载
评论 #13540572 未加载
petetnt超过 8 年前
Popovs argument seems to contradict his statement as seen in this other Motherboard article: <a href="https:&#x2F;&#x2F;motherboard.vice.com&#x2F;read&#x2F;this-pro-trump-russian-is-spamming-google-analytics" rel="nofollow">https:&#x2F;&#x2F;motherboard.vice.com&#x2F;read&#x2F;this-pro-trump-russian-is-...</a><p>Before:<p>&gt; “I was fully prepared from April, but I wait. I could begin in a month before the elections and on a wave of the anti-Russian hysteria to receive a lot of traffic,” he said.<p>Later:<p>&gt; “Lie! Not my domain!” Popov writes in bright red text regarding the site with dodgy pop-ups.<p>&gt; “Lie! I&#x27;m not a spammer!” he continues.<p>Either someone is running an extensive anti-Popov campaign or Popov is realising that the campaign has been a huge mistake.
评论 #13540279 未加载
merricksb超过 8 年前
Cached version (as original URL is returning 404):<p><a href="http:&#x2F;&#x2F;webcache.googleusercontent.com&#x2F;search?q=cache:KZq3KBVYLhYJ:motherboard.vice.com&#x2F;read&#x2F;google-is-battling-a-russian-spammer-over-the-use-of-the-letter-g+&amp;cd=1&amp;hl=en&amp;ct=clnk&amp;gl=au" rel="nofollow">http:&#x2F;&#x2F;webcache.googleusercontent.com&#x2F;search?q=cache:KZq3KBV...</a>
ungzd超过 8 年前
Seems that they sued vice.com too, now displays 404.
hlandau超过 8 年前
I can&#x27;t believe it took this long for someone to register that name.
评论 #13540202 未加载
runnr_az超过 8 年前
My coworker built a little tool to identify potential domain spam problems: <a href="http:&#x2F;&#x2F;upsidedown.domains&#x2F;alternate.html?google" rel="nofollow">http:&#x2F;&#x2F;upsidedown.domains&#x2F;alternate.html?google</a>
krumplifej超过 8 年前
I stumbled upon this vulnerability during a white hat phishing test. The success rate was very high when I used the alternate G domains even among hard core IT folks. People have a tendency to overlook the difference. At that point I faced an ethical dilemma: should I just forget about this or maybe publish something? Neither options seemed right. Finally decided to get all the unreserved domain names for the fortune 500. Had to set a limit somewhere... To my surprise 102 of the vulnerable 103 fortune 500 was still available. Now I own these domains... If these companies want them, I am happy to transfer them over. If they do not care, I just let them expire. For my company - we set the spam filters according, changed our web proxies, and also own the alternate domains. I also submitted a bug report with a major software vendor, because their solution further amplified the problem. They are working on a fix...
NKCSS超过 8 年前
unicode in domains is tricky; on the one hand; it&#x27;s good that we can allow people whom have non-ascii characters in their language to create domains using them, but it introduces the problems pointed out here. It would be sane to say that, when you abuse the system to trick people (as is clear with the google and lifehacker examples), that the registration is voided (and barred from future use).<p>Maybe it should be restricted to certain TLD&#x27;s though; e.g. only allow the unicode characters in TLD&#x27;s that have a good reason for using them. That way, it won&#x27;t be an issue for .com&#x2F;.net&#x2F;etc.
评论 #13540134 未加载
评论 #13540416 未加载
annnnd超过 8 年前
Is it possible to disable Unicode chars for domains in FF?
评论 #13540321 未加载
rnhmjoj超过 8 年前
I get a &quot;404 horse&quot;.
评论 #13540290 未加载
homero超过 8 年前
Vice is under ddos now