Hacker News new | ask | show | jobs
by watashiato 1098 days ago
Here's the original source by the author: https://scribe.rip/@bobbyrsec/the-dangers-of-googles-zip-tld...

While I think that we really don't need a .zip domain, this trick falls apart when not shown as an image. Hovering over either URL should tip you off. Firefox shows the actual link in the bottom left.

3 comments

> Hovering over either URL should tip you off. Firefox shows the actual link in the bottom left.

Most people don't even know what a URL is, let alone how to discover this kind of deception by looking at the hover info.

at that point you can just use a regular hyperlink without showing the url on the page at all.
This so-called attack is also not as effective in most contexts as the simple <a href="https://evilsite.com">https://goodsite.com</a> trick. Raw URLs in web pages don't get auto-linkified anyway, so something is turning it into a link (e.g. through use of HTML), and at that point you can have the link text and the URL be whatever you want, completely independently of each other.
How exactly does this trick work? Thing is, a URL can't have any non-ASCII characters in it. So this would only happen if the webpage or some app takes the URL and undoes the percent-encoding to try to make it more readable.
I just tried the fake URL by pasting it into Safari's address bar, and it “helpfully” percent-encoded the special slashes and tried to go to v1271.zip.