Chipp.in Tech News and Reviews

Windows, Security & Privacy, Open Source and more

Menu
  • Home
  • Windows
  • Security & Privacy
  • Gaming
  • Guides
  • Windows 11 Book
  • Contact
  • RSS Feed
Menu

This uBlock Origin filter blocks IDN attacks in browsers

Posted on October 20, 2023October 20, 2023 by Martin Brinkmann

IDN attacks are a common threat on today’s Internet. IDN stands for Internationalized Domain Name. It refers to domain names that contain one or multiple characters in “non-Latin script or alphabet, or in the Latin alphabet-based characters with diacritics or ligatures”.

This enables support for domain names in all languages. German-speaking organizations and users may for instance use the letter Ö in domain names.

One problem associated with this is that it is sometimes impossible for users to distinguish between different characters. The Latin letters e and a, for instance, look identical to the Cyrillic letters e and a. The strings ghacks and ghаcks are not identical, for example, even though they are not distinguishable from just looking at them.

IDN homograph attacks

IDN homograph attacks take advantage of this. Threat actors create domain names that look like a legitimate domain. Links are then pushed via online advertising, comments, chats, email or other forms of communication.

Ars Technica published a story just yesterday about an online ad on Google Search that impersonated the official KeePass website. A search for KeePass listed a sponsored result at the top. This sponsored result pointed to the same domain as the legitimate KeePass website, at least on visual inspection.

It is not uncommon for organizations to place ads for key search terms, even if their domain is the first organic result.

In this particular case, it turned out that the sponsored ad was malicious. It used an IDN to look like the official KeePass website. The fake site pushed a malware family known as FakeBat according to Ars Technica’s research.

Protection against IDN attacks

blocked IDN attacks example

Ars Technica writer Dan Goodin concluded that there is no 100% protection against IDN attacks. All major browsers load IDN URLs without issues.

Chromium-based browsers copy the punycode version of the domain, which offers a quick way to find out if it is an IDN.

Raymond Hill, creator of uBlock Origin, disagreed with Goodin’s conclusion as well. He published a single filter line for use in uBlock Origin, which blocks access to all IDN URLs by default. Users still have the option to proceed and to add an exception for the site, if it is legitimate.

Here is a step-by-step guide to add the filter to uBlock Origin:

  • Open the web browser.
  • Activate the uBlock Origin icon and select Settings.
  • Switch to the My Filters tab.
  • Paste the following string into an empy line: ||xn--$doc,frame
  • Select Apply changes.

That’s all there is to it. Any attempt to load an IDN in the browser is now met with uBlock Origin’s “blocked” window.

Tags:
Category: Security & Privacy

Post navigation

← Disable OneDrive’s Back up folders on this PC feature
Password Managers that restrict passwords should not exist →

2 thoughts on “This uBlock Origin filter blocks IDN attacks in browsers”

  1. Tom Hawack says:
    October 20, 2023 at 10:12 pm

    Punnycode, IDN … I had that out of my mind for quite some time now.
    This uBO filter is welcomed of course, most welcomed notably regarding the article.

    Reply
  2. Keith Pounds says:
    November 10, 2023 at 5:05 am

    Thank you Martin! Great tip.

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • October 17, 2025 by Martin Brinkmann Mozilla will continue to support Firefox on Windows 10
  • October 16, 2025 by Martin Brinkmann Firefox: how to delete files download in private browsing automatically
  • October 15, 2025 by Martin Brinkmann How to change the number of videos YouTube shows per row
  • October 13, 2025 by Martin Brinkmann Amazon seems to turn Echo Show devices into personal advertisement billboards for your home
  • October 12, 2025 by Martin Brinkmann Windows 11, Version 23H2 Home and Pro will stop getting updates starting next month

About

We talk, write and dream about Technology 24/7 here at Chipp.in. The site, created by Martin Brinkmann in 2023, focuses on well-researched tech news, reviews, guides, help and more.

Legal Notice

Our commitment

Many websites write about tech, but chipp.in is special in several ways. All of our guides are unique, and we will never just rehash news that you find elsewhere.

Read the About page for additional information on the site and its founder and author.

Support Us

We don't run advertisement on this site that tracks users. If you see ads, they are static links. Ads, including affiliate links, never affect our writing on this site.

Here is a link to our privacy policy

©2025 Chipp.in Tech News and Reviews