Security consideration: math symbols in an exotic IP address format in a phishing mail

Marius Spix marius.spix at web.de
Sat May 16 18:43:17 CDT 2020


Today I received an interesting phishing mail which had an URL
containing mathematical bold numbers. Interestingly the address
πŸŽπŸ“πŸ”πŸ•πŸπŸ‘πŸ”πŸŽπŸ‘πŸŽπŸ was interpreted as an octal number 05671360302, which is
another spelling for 46.229.224.194. This worked for both Firefox and
Chrome. I don’t know why such an address is accepted in the authority
part of a HTTPS URI of current browsers. Section 7.4 in RFC 3986 states
that additional IP address formats can become a security concern, but
it also says that literals should be converted to numeric form.

I wonder if this case should be added to UTR #36.

Regards

Marius




More information about the Unicode mailing list