Reference: http://thehackernews.com/2017/04/unicode-Punycode-phishing-attack.html?m=1
That true. A new kind of Phishing is Almost Impossible to Detect On Chrome, Firefox and Opera
When you enter to your homebanking or some relevant site, surely you always check:
Its ok to verify this always. But take a look of this images:
Someone has discover a vulnerabily in browsers, you can registers domanis with other language characters and they shows as normal english characters on the web browser.
look at the image, in both i enter to apple.com (well the browser shows that, i dont do any trick)
That is the phishing.
One url in fact is www.apple.com
The other is https://www.xn--80ak6aa92e.com/ but the browser shows apple.com
ADVICES:
*Always check URL and the source of the certificate. *
*Never enter importat sites from external links (from emails or msgs)
*Be smart
Please thake a look of this article
SOURCE: http://thehackernews.com/2017/04/unicode-Punycode-phishing-attack.html?m=1