So there is this recently identified security problem (now fixed in recent updates to many browsers) that allows(ed) a faked URL to appear exactly the same as the real URL in your browser's address bar. A harmless test below will tell you if your browser is vulnerable.

A spoofed URL:

Click here to enter what looks like the real Shmoo Group, but which is faked

The above should look like "http://www.xn--theshmogroup-bgk.com/" in your address bar if you have FireFox 1.0.1, or the latest version of Mac's Safari, or possibly other recently updated versions of browsers installed.

If you don't have Firefox 1.0.1 or other recently updated browsers, the above will probably be indistiguishable from the non-faked link below:


The real URL:

Click here to enter the real Shmoo Group


(The Shmoo Group is a non-profit think-tank comprised of security professionals from around the world who donate their free time and energy to information security research and development.)

More detailed reading about the exploit:

IDN advisory - Update 2/11/05
Initial IDN advisory