OWASP / OWASP/ASVS

Phishing and/or visual deception protections

Open
#3,338 16 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

4) proposal for review V1 (prev V5)
Dominant language
HTML
Stars
3.6k
Forks
831
Avg merge
7h 55m
Merged PRs (30d)
4

Description

I was reading this article from Wiz the other day, and the use of homoglyphs for deception stuck with me because I've tackled the same problem many years ago.

That particular issue is easy to solve (for any authoritative names, have validations that don't allow mixing of alphabets), but surely we can research and distill other similar requirements. ASVS currently doesn't have any, and I can't think of a good reason why not. Perhaps just over-focusing on pure programming logic?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading the linked Wiz article and reviewing the existing ASVS requirements to identify how phishing, homoglyphs, and visual deception are currently covered. The work is complete when the project agrees on concrete, actionable verification requirements and their appropriate place in ASVS.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.