elceef / dnstwist

Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation
https://dnstwist.it
Apache License 2.0
4.81k stars 764 forks source link

Feature: Look-alike letters from non-Latin alphabets? #225

Open nycalex opened 2 months ago

nycalex commented 2 months ago

Hi, I really like this tool, but i wonder if you consider detecting look-alike letters from other alphabets?

Take aррle.com for example. Looks just like apple.com, doesn't it? But the two pp are actually the Cyrillic alphabet рр and it treated by dns differently, effectively it's a separate domain

Same can be done with Cyrillic о, к, у, е, н, в, а, с, т

elceef commented 1 month ago

IDN domain names mixing characters (Latin and Cyrillic in this case), despite being punycode encodable, can't be registered in practice due to domain registrar policies.

$ whois xn--ale-0eda.com
No match for domain "XN--ALE-0EDA.COM".