Skip to content

runningdemo/real_domain_name

Repository files navigation

Show Real Domain Name

Show real domain name of the current webpage.

Install on Chrome Web Store

screenshot

screenshot

screenshot

Why it's important?

demo

As you can see both of these domains appear identical in the browser but they are completely different websites. One of them was registered by us, today. Our epic.com domain is actually the domain https://xn--e1awd7f.com/ but it appears in Chrome and Firefox as epic.com.

The real epic.com is a healthcare website. Using our unicode domain, we could clone the real epic.com website, then start emailing people and try to get them to sign into our fake healthcare website which would hand over their login credentials to us. We may then have full access to their healthcare records or other sensitive data.

Quoted from wordfence.com post

I recommended you install this plugin because We don't know when the browser will screw things up again.

Updates: Update on April 19th at noon Pacific time: Chrome has just released version 58.0.3029.81. We have confirmed that this resolves the issue and that our ‘epic.com’ test domain no longer shows as ‘epic.com’ and displays the raw punycode instead, which is ‘www.xn--e1awd7f.com’, making it clear that the domain is not ‘epic.com’. We encourage all Chrome users to immediately update to the above version of Chrome to resolve the issue. The original post follows:

I don't trust this plugin?

This plugin is open sourced, check it here: https://github.com/runningdemo/real_domain_name

More discussion here:

https://www.wordfence.com/blog/2017/04/chrome-firefox-unicode-phishing/

About

No description, website, or topics provided.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published