A new open-source tool named Tirith has been released to detect homoglyph attacks within command-line environments by analyzing URLs in typed commands and preventing their execution, based on information published by Bleeping Computer.Tirith operates by integrating with various shells such as zsh, bash, fish, and PowerShell, scrutinizing every command pasted for execution. This functionality aims to block deceptive attacks that leverage URLs containing characters from different alphabets that appear identical to users but are recognized as distinct by computers. Attackers can exploit this to create domain names that mimic legitimate brands, leading users to malicious servers. While browsers have implemented defenses, terminals remain vulnerable due to their rendering of Unicode, ANSI escapes, and invisible characters.Tirith is designed to detect and block a range of threats including homograph attacks, terminal injection, pipe-to-shell patterns, dotfile hijacking, insecure transport, supply-chain risks, and credential exposure.Source: Bleeping Computer
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
Related Terms
AdwareYou can skip this ad in 5 seconds
