Domain name sytem offers back door to criminals

Phishers could hijack new domain name system

Dinah Greek

A recently approved system that allows countries to create web addresses using a mixture of European and non-European languages could open a back door for scammers warned the UK Internet Forum (UKIF).

People are directed to websites by the real name rather than as websies internet protocol address, which is a series of numbers. European languages use what are called ASCII codes to create 'real name' web addresses and other languages such as Russian, Greek or Chinese use a code called Unicode. The Internationalised Domain Names (IDN) system now combines these.

Advertisement

The problem for consumers is some of the letters in the alphabets that use Unicode is they resemble those used in European alphabets. The worry is criminals will use a mixture of these codes to register websites that look like those that belong to legitimate companies and direct users to the fake sites. Steve Dyer, director of UKIF told Compueractive there were reals concerns about misuse of this by criminals. "The Russian 'A' looks just the same as the English 'A' although it means something different. A criminal could register a domain name using a mixture of ASCII and Unicode that is indistinguishable to the ordinary surfer from the genuine site.

"To prove a point, the website PayPal was created using a mixture of the European and Russian alphabet. People were directed to a fake site and phishers can steal personal details. This site was handed over to PayPal but shows how dangerous this could become",he said.

But the IDN system can't just be binned he warned as other countries genuinely need a way to write 'real names' for their websites because it is easier for people to use. He also said some legitimate sites, such as More Than (More>) and Toys R Us use non-European letters to denote their brand.

Mr Dyer said the internet industry must be more aware of the risks.

But he believed there are safeguards that could alert internet users. Browsers for example could flag up sites that use a mixture of ASCII and Unicode and he said Opera believe it has safeguards and Mozilla is working on a solution.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

New domains cause wrangles

New domains irk analysts

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

IT white papers

Search white papers

Top categories

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file...

Dell Adamo XPS

Dell launches ultra-thin Adamo XPS

World's thinnest laptop will be available by Christmas

Top 10 articles, 6 November 2009

The worst Microsoft products of all time, and a USB...

Iain Thomson

Pirate Bay shutdown could be inspiring online militancy

Recent Swedish attacks raise worrying possibility

Primary Navigation