• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - Outlook security vulnerability allows unscrupulous people to conduct phishing scams with fake IDNs

Outlook security vulnerability allows unscrupulous people to conduct phishing scams with fake IDNs

Claire by Claire
September 8, 2021 - Updated on August 4, 2026
in Anti-Virus Software and Internet Security

When you receive an email, you check to see if the sender is from a trusted source, but is what appears true? That’s not necessarily the case. In the past, it was common to see similar-shaped letters and numbers used to confuse the real ones, making it difficult to tell the real ones. Now there is a more powerful trick, starting directly from the IDS and using different language methods to alter the data, instead of mixing the traditional email address with numbers and letters.

Outlook security vulnerability allows unscrupulous people to conduct phishing scams with fake IDNs

The contact information related to IDS (Internationalized Domain Name) can be displayed in Outlook’s mailing address. It seems that the content is detailed and easy to gain trust. However, IDS accepts not only English letters and numbers, but also letters from other languages ​​that are very similar to Latin letters in appearance, such as Cyrillic letters. Security researcher DobbyWanKenobi is atPersonal blogHe wrote that he discovered a vulnerability in Outlook that allowed him to send phishing emails that were misleading at first sight.

I recently found a bug in the Address Book component of Microsoft Office for Windows that allowed me to send convincing phishing emails! https://t.co/wEm2aHFzXj

— DobbyWanKenobi (@dobby1kenobi) September 1, 2021

The concept of IDN was proposed in 1996 to expand the domain name space to non-Latin languages ​​and deal with the ambiguity of different characters that look identical in shape to the Latin alphabet. IDNs can also easily represent the Internationalized Domain Name Encoding (Punycode) version of a function variable name in ASCII form, where there is no ambiguous area between two similar domain names. DobbyWanKenobi found that half of this is not very clear in Microsoft Outlook. When displaying the sender’s contact information, the address book function does not make any distinction. Mike Manzotti of security agency Dionach also followedpublished his research, below we can see that the test sender on his side looks like it is coming from a trusted source “onmicrosoft.com”, when in fact it is coming from “onmìcrosoft.com” (note the difference in i and ì). In addition, the contact information in the address book can be changed in different languages ​​​​to confuse the recipient’s audio and video.

The reason for this is that Outlook does not properly validate the Multipurpose Internet Mail Extensions (MIME) header. When you send a message, you can specify the SMTP sender address and the sender’s MIME, because MIME is wrapped in the SMTP protocol. But according to Manzotti, Microsoft Office Outlook 365 fails to properly validate internationalized domain names, allowing attackers to impersonate any valid contact in the target organization.

Researchers discovered that this vulnerability affects both 32-bit and 64-bit versions of Windows 365. However, after notifying Microsoft, Microsoft responded to Manzotti that it would not fix this vulnerability in the current version. In fact, Microsoft has already started to fix it early. Starting from Outlook 16.0.14228.20216, this vulnerability will no longer exist. It is recommended that everyone update Outlook to the latest version and be vigilant against such phishing scams.

◎Data source:ArsTechnica

 

Source: KOCPC Chinese

Tags: Internet securityMicrosoftMicrosoft 365OutlookPhishingPhishing scam

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology