iconAll times are GMT. The time now is 03:05. | Welcome to aberdeen-music! Please register for free in order to access all areas of the web site and to post on our forums.


» Forums » Other Forums » General Discussion » Got Firefox???

General Discussion Forums for all discussion about everything else non-music or scene related.

Reply
 
LinkBack Thread Tools
Old 08-02-2005, 17:10   #1 (permalink)
Neubeatz


Profile
joined:
posts: n/a

Default Got Firefox???

FireFox fans across the world, grab the Kleenex!

According to a paper recently published by Eric Johanson of the Shmoo Group, users on most Mozilla-based browsers (Firefox 1.0, Camino .8.5, Mozilla 1.6, etc), Safari 1.2.5, Opera 7.54, Omniweb 5 are victim to a complex International Domain Name [IDN] spoof.

This new attack allows an attacker/phisher to spoof the domain/URLs of businesses. Every recent gecko/khtml based browser implements IDN (which is just about every browser except for Internet Explorer). The Smoo Group have created a proof of concept where the links are directed at "http://www.pаypal.com/", which the browsers punycode handlers render as www.xn--pypal-4ve.com.

According to the group there is however an easy to way to detect you're under a spoof attack, cut & paste the url you are accessing into notepad or some other
tool (under OSX, paste into a terminal window) which will allow you to view what character set/pagecode the string is in. You can also view the details of the SSL cert etc.

You can disable IDN support in Mozilla products by setting 'network.enableIDN' to false. There is no known workaround for Opera or Safari. Vendor responses have been varied with VeriSign and Apple failing to respond but Opera believing they have correctly implemented IDN, and will not be making any changes (oops). Mozilla are currently working on finding a good long-term solution. The company provided a clear workaround for disabling IDN temporarily until it can better address the issue.

This latest exploit will provide spammers with a way to trick FireFox, Opera and Safari users into thinking they're on a certain website. Commonly known as Phishing this latest attack by spammers and hackers is frighteningly common.

Update: Many users are reporting the config change in Firefox does not work, currently there is no fix for Firefox.



Links:
http://www.neowin.net/comments.php?i...&category=main

http://www.kleenex.com/home.htm
http://en.wikipedia.org/wiki/Phishing
http://www.shmoo.com/idn/homograph.txt
  Reply With Quote
Old 08-02-2005, 17:13   #2 (permalink)

 
Hogisbald's Avatar

Hogisbald is a name known to all with 155 reputation points.Hogisbald is a name known to all with 155 reputation points.Hogisbald is a name known to all with 155 reputation points.Hogisbald is a name known to all with 155 reputation points.Hogisbald is a name known to all with 155 reputation points.Hogisbald is a name known to all with 155 reputation points.

Profile
Male
location: In Devin Heaven
joined: Aug 2003
posts: 8,662
bands: Element 106 and solo stuff
talents: Guitar

Default

You geek!!!
Hogisbald is offline   Reply With Quote
Old 08-02-2005, 17:19   #3 (permalink)
Zeenat Aman


Profile
joined:
posts: n/a

Default

Grrr, computers are never going to be safe, especially for people who have no real knowledge about them... like me!

I look forward to my next paypal payment going straight into the pocket of some lil shit in the states or whatever!?
  Reply With Quote
Old 08-02-2005, 17:23   #4 (permalink)

 
Dave's Avatar

Profile
Male
location: Aberdeen
joined: Jun 2004
posts: 3,415
talents: I am at two with nature

Default

I didn't understand a word of that. I can just about get my head around the "on" switch.
Dave is offline   Reply With Quote
Old 08-02-2005, 17:25   #5 (permalink)

 
Lawy Lawson:Attorney's Avatar

Lawy Lawson:Attorney is on a distinguished road with 10 reputation points.

Profile
location: Aberdeen
joined: Mar 2004
posts: 705

Default

Should I back the internet up to disk or is it still safe to use the same internet as my neighbour?
Lawy Lawson:Attorney is offline   Reply With Quote
Old 08-02-2005, 18:17   #6 (permalink)

 
psydoll's Avatar

psydoll is well respected with 54 reputation points.psydoll is well respected with 54 reputation points.psydoll is well respected with 54 reputation points.

Profile
Male
location: You're never there when I call
joined: Mar 2004
posts: 7,442
bands: AKA Crap Boyfriend, Gnome Meets Crowbar
talents: Annoyance

Send a message via MSN to psydoll
Default

Quote:
Originally Posted by Lawy Lawson:Attorney
Should I back the internet up to disk or is it still safe to use the same internet as my neighbour?
I hope thou hasn't been coveting thy neighbour's Internet.
psydoll is offline   Reply With Quote
Old 08-02-2005, 18:37   #7 (permalink)

 
Teabags's Avatar

Teabags is a community guru with 253 reputation points.Teabags is a community guru with 253 reputation points.Teabags is a community guru with 253 reputation points.Teabags is a community guru with 253 reputation points.Teabags is a community guru with 253 reputation points.Teabags is a community guru with 253 reputation points.Teabags is a community guru with 253 reputation points.Teabags is a community guru with 253 reputation points.

Profile
Male
location: The Moorings
joined: Aug 2003
posts: 4,325
bands: bullet belt bastards

Send a message via MSN to Teabags
Default

Quote:
Originally Posted by psydoll
I hope thou hasn't been coveting thy neighbour's Internet.
nah he's been humping his bum bum.
Teabags is offline   Reply With Quote
Old 08-02-2005, 21:36   #8 (permalink)

 
MattJimF's Avatar

MattJimF is a helpful contributor with 28 reputation points.MattJimF is a helpful contributor with 28 reputation points.

Profile
Male
location: Aberdeen
joined: Feb 2004
posts: 1,053

Default

work around here http://forums.mozillazine.org/viewto...ight=idn+spoof
MattJimF is offline   Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Mozilla Firefox menu Teabags General Discussion 1 24-01-2005 11:59
Firefox Extension che Comments & Suggestions 2 31-10-2004 19:45


Inactive Reminders By Icora Web Design