-
Dear felow researchers,
Any advice? |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
Hi Stefano, The results from your homoglyph fuzzer include Internationalized Domain Names (IDNs) encoded in Punycode, identifiable by the
While useful for international domains, Punycode is often exploited for phishing by creating visually similar domains, such as replacing The homoglyph fuzzer in You can also use tools like DomainTools to verify these domain names and gather additional information about them. Implementing proper monitoring and manual filtering can help you stay ahead of potential threats posed by these flagged domains. Kind regards, |
Beta Was this translation helpful? Give feedback.
-
Hi Ygal Thank you |
Beta Was this translation helpful? Give feedback.
Hi Stefano,
The results from your homoglyph fuzzer include Internationalized Domain Names (IDNs) encoded in Punycode, identifiable by the
xn--
prefix. This encoding converts non-ASCII characters (e.g.,á
,ñ
, or Cyrillic letters) into a DNS-compatible format. For example:While useful for international domains, Punycode is often exploited for phishing by creating visually similar domains, such as replacing
a
(Latin) withа
(Cyrillic).The homoglyph fuzzer in
dnstwist
cannot excludexn--
domains, so you’ll need to manually filter these from your results. Attackers often use Punycode to mimic legitimate domains in browsers, making domains like…