:D
:D
Maybe a low hit rate, but if you could automate it, you could run the scam on a lot of places.
Presumably this would trick users who would go check "C:\windows\system32\drivers\etc\" but not show hidden files. Seems like a niche subset, but still a neat trick.
As a concrete example, the following are fake links to Wikipedia (and entirely equivalent):
http://xn--wkd-8cdx9d7hbd.org (FAKE, same as below)
http://www.wіkіреdіа.org (FAKE, same as above)
It is true that network protocols encode these internationalized domain names in a subset of ASCII, but the user sees Unicode in his browser address bar or email. There is no restriction on how applications (like browsers) display domain names[2]; they can use Unicode if they want. This lead to all sorts of devious attacks[3].
[1] https://en.wikipedia.org/wiki/Domain_name#Internationalized_...
[2] https://en.wikipedia.org/wiki/Internationalized_domain_name#...
https://codepoints.net/search?q=https%3A%2F%2Fwww.google.com...