Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Non-Microsoft Browsers Have Spoofing Flaw
Netcraft ^ | 2/7/2005 | Netcraft

Posted on 02/07/2005 11:29:30 AM PST by KwasiOwusu

All non-Microsoft browers include a flaw that allows URL spoofing using Unicode characters, which can be exploited by phishing scams seeking to steal login information for online banking accounts. The spoofing flaw, which is demonstrated on the web site of the Shmoo Group, works in the Firefox, Mozilla and Opera browsers, as well as the Safari browser for Macs.
The spoof exploits flaws in how the browsers interpret Unicode characters. A link using Unicode characters to replace the letter "a" in "Paypal" will display as www.paypal.com in the browser, but send users to www.xn--pypal-4ve.com - which then displays "www.paypal.com" in its address bar. A similar spoof works on SSL-enabled URLs (https) commonly used on banking and e-commerce sites.

Unicode is a broader character set that includes non-English characters as well as symbols, which is being used on the Internet to support Internationalized Domain Names (IDN). The affected browsers support IDN, while Microsoft's Internet Explorer does not.

(Excerpt) Read more at news.netcraft.com ...


TOPICS: Business/Economy; News/Current Events; Technical
KEYWORDS: browsers; computersecurity; firefox; gateslapdog; iuseamacsoiambetter; kneepads; littleprecious; lowqualitycrap; marrymebill; microsoft; microsoftastroturf; mskneepadbrigade; netscape; paidshill; redmondianrobots; redmondpayroll; redmondstooge; safari; trollfromredmond; wontyoumarrymebill
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-80 ... 201-213 next last
Nice. :)
1 posted on 02/07/2005 11:29:30 AM PST by KwasiOwusu
[ Post Reply | Private Reply | View Replies]

To: KwasiOwusu

We've been repeatedly told that this couldn't happen with Firefox and Mozilla. That everything is M$' fault. Oh the inhumanity of it all.


2 posted on 02/07/2005 11:31:27 AM PST by Diplomat
[ Post Reply | Private Reply | To 1 | View Replies]

To: KwasiOwusu

Uh-oh! I guess they've finally figured out that enough people are using non-MSFT browsers to make them worthwhile targets.

Me, I stick with Internet Exploder. At least I know its vulnerabilities. Folks that think their browser-of-the-month is invulnerable are just guessing.

And now we have a new way to fool them. Oh well....


3 posted on 02/07/2005 11:31:50 AM PST by MineralMan (godless atheist)
[ Post Reply | Private Reply | To 1 | View Replies]

To: KwasiOwusu

oopsie
All those millions who downloaded Firefox- and heralded it as a 'huge success' (for giving something away??) better warn everyone


4 posted on 02/07/2005 11:31:56 AM PST by Mr. K
[ Post Reply | Private Reply | To 1 | View Replies]

To: KwasiOwusu

From the above referenced article - "...The attack can be disabled in Firefox and Mozilla by setting 'network.enableIDN' to false in the browser's configuration (enter about:config in the address bar to access the configuration fucntions). "

---

There are some folks here who are big fans of Firefox.


5 posted on 02/07/2005 11:32:25 AM PST by contemplator
[ Post Reply | Private Reply | To 1 | View Replies]

To: KwasiOwusu

I never put personal info on a site that I have been linked to. I only go to those sites directly.


6 posted on 02/07/2005 11:32:32 AM PST by SlowBoat407 (Speculating idiot)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Diplomat

bttt


7 posted on 02/07/2005 11:33:09 AM PST by Ff--150 (It Works!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: KwasiOwusu
The attack can be disabled in Firefox and Mozilla by setting 'network.enableIDN' to false in the browser's configuration (enter about:config in the address bar to access the configuration fucntions).
8 posted on 02/07/2005 11:33:58 AM PST by TheOtherOne
[ Post Reply | Private Reply | To 1 | View Replies]

To: KwasiOwusu

THAT'S IT!!!!

I'VE HAD ENOUGH!!!!

I am giving up all browsers!!!!

I am going back to pen and paper and stamps.

Now would everyone on Free Republic be so kind as to send me your physical address so I can correspond with you and send you newspaper clippings...


9 posted on 02/07/2005 11:34:03 AM PST by PetroniusMaximus
[ Post Reply | Private Reply | To 1 | View Replies]

To: contemplator

bump for later


10 posted on 02/07/2005 11:34:46 AM PST by rocksblues (Liberalism is a sickness not a political ideology)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Diplomat
We've been repeatedly told that this couldn't happen with Firefox and Mozilla. That everything is M$' fault. Oh the inhumanity of it all.

Of course, the reason it affects all of them couldn't be Microsoft's unicode-handling API, could it?

11 posted on 02/07/2005 11:34:52 AM PST by kevkrom (If people are free to do as they wish, they are almost certain not to do as Utopian planners wish)
[ Post Reply | Private Reply | To 2 | View Replies]

To: KwasiOwusu
Everyone should be happy to know that the Lynx text browser doesn't seem to suffer from this problem...
12 posted on 02/07/2005 11:35:36 AM PST by Question_Assumptions
[ Post Reply | Private Reply | To 1 | View Replies]

To: KwasiOwusu

Nevermind the fact this is a configuration setting that can be turned off right?


13 posted on 02/07/2005 11:36:11 AM PST by N3WBI3
[ Post Reply | Private Reply | To 1 | View Replies]

To: KwasiOwusu

Thnak you Mr. Gates for posting this.


14 posted on 02/07/2005 11:37:51 AM PST by ElkGroveDan
[ Post Reply | Private Reply | To 1 | View Replies]

To: kevkrom

Right, it's Microsoft fault Firefox fails. Why is Firefox even using Microsoft unicode-handling API? hmmm. Me thinks Firefox could do it on their own.


15 posted on 02/07/2005 11:38:16 AM PST by Diplomat
[ Post Reply | Private Reply | To 11 | View Replies]

To: N3WBI3

It can, just like many exploits in archnemesis IE. Unfortunately, anyone stupid enough to fall for a phishing scam is also WAY too stupid to reconfigure their browser.


16 posted on 02/07/2005 11:39:04 AM PST by Doohickey ("This is a hard and dirty war, but when it's over, nothing will ever be too difficult again.”)
[ Post Reply | Private Reply | To 13 | View Replies]

To: RhoTheta

Nothing about LYNX on here, so I guess I'm OK.


17 posted on 02/07/2005 11:39:39 AM PST by Egon (Government is a guard-dog to be fed, not a cow to be milked.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Diplomat
"We've been repeatedly told that this couldn't happen with Firefox and Mozilla. That everything is M$' fault. Oh the inhumanity of it all"

Yep.
Its gotta be Bill Gates's fault.
Its bad ole Bill that did it.
LMAO!!
18 posted on 02/07/2005 11:39:51 AM PST by KwasiOwusu
[ Post Reply | Private Reply | To 2 | View Replies]

To: KwasiOwusu

LOL!


19 posted on 02/07/2005 11:40:01 AM PST by Echo Talon (http://echotalon.blogspot.com/)
[ Post Reply | Private Reply | To 1 | View Replies]

To: KwasiOwusu

Hey everybody, this is true, so true. Firefox is too dangerous for you to use. Please do not switch to Firefox. Alas, it is too late for me. So lets just keep the status quo. Thanks.


20 posted on 02/07/2005 11:40:14 AM PST by Arkinsaw
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-80 ... 201-213 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson