Domain name sytem offers back door to criminals

Phishers could hijack new domain name system

Dinah Greek

A recently approved system that allows countries to create web addresses using a mixture of European and non-European languages could open a back door for scammers warned the UK Internet Forum (UKIF).

People are directed to websites by the real name rather than as websies internet protocol address, which is a series of numbers. European languages use what are called ASCII codes to create 'real name' web addresses and other languages such as Russian, Greek or Chinese use a code called Unicode. The Internationalised Domain Names (IDN) system now combines these.

Advertisement

The problem for consumers is some of the letters in the alphabets that use Unicode is they resemble those used in European alphabets. The worry is criminals will use a mixture of these codes to register websites that look like those that belong to legitimate companies and direct users to the fake sites. Steve Dyer, director of UKIF told Compueractive there were reals concerns about misuse of this by criminals. "The Russian 'A' looks just the same as the English 'A' although it means something different. A criminal could register a domain name using a mixture of ASCII and Unicode that is indistinguishable to the ordinary surfer from the genuine site.

"To prove a point, the website PayPal was created using a mixture of the European and Russian alphabet. People were directed to a fake site and phishers can steal personal details. This site was handed over to PayPal but shows how dangerous this could become",he said.

But the IDN system can't just be binned he warned as other countries genuinely need a way to write 'real names' for their websites because it is easier for people to use. He also said some legitimate sites, such as More Than (More>) and Toys R Us use non-European letters to denote their brand.

Mr Dyer said the internet industry must be more aware of the risks.

But he believed there are safeguards that could alert internet users. Browsers for example could flag up sites that use a mixture of ASCII and Unicode and he said Opera believe it has safeguards and Mozilla is working on a solution.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

New domains cause wrangles

New domains irk analysts

Related whitepapers

Related jobs

Most watched

vodafone logo

Vodafone talks up mobile app development

V3.co.uk took its video camera along to a recent Vodafone 360 Developer Day in Sheffield

RSA 2010: Security predictions for the coming year

Execs share their thoughts on what 2010 may hold

Analysis and Reports

Continuous Availability for Microsoft SharePoint

This paper examines how to create continuous availability for Microsoft SharePoint by implementing high availability and disaster recovery solutions.

Database security: Preventing enterprise data leaks at the source

This report looks at the challenge of information protection and control (IPC) and how enterprises must adopt database security best practices

Poll

International Women’s Day poll

International Women’s Day poll

Have measures to encourage women into the IT profession been successful?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

Charles Thacker [photo: Marcin Wichary]

Microsoft researcher lands Turing Award

Charles Thacker scoops technology Nobel

vodafone logo

Vodafone talks up mobile app development

V3.co.uk took its video camera along to a recent Vodafone...

Web domain

Nominet consults on short .uk domain names

Registry gears up for one-letter, two-letter and single-number domains

Jim Stikeleather

Interview: Dell Perot Systems CTO Jim Stikeleather

We chat to Jim Stikeleather about cyber security and the...

Primary Navigation