Skip to comments.
Non-Microsoft Browsers Have Spoofing Flaw
Netcraft ^
| 2/7/2005
| Netcraft
Posted on 02/07/2005 11:29:30 AM PST by KwasiOwusu
All non-Microsoft browers include a flaw that allows URL spoofing using Unicode characters, which can be exploited by phishing scams seeking to steal login information for online banking accounts. The spoofing flaw, which is demonstrated on the web site of the Shmoo Group, works in the Firefox, Mozilla and Opera browsers, as well as the Safari browser for Macs.
The spoof exploits flaws in how the browsers interpret Unicode characters. A link using Unicode characters to replace the letter "a" in "Paypal" will display as www.paypal.com in the browser, but send users to www.xn--pypal-4ve.com - which then displays "www.paypal.com" in its address bar. A similar spoof works on SSL-enabled URLs (https) commonly used on banking and e-commerce sites.
Unicode is a broader character set that includes non-English characters as well as symbols, which is being used on the Internet to support Internationalized Domain Names (IDN). The affected browsers support IDN, while Microsoft's Internet Explorer does not.
(Excerpt) Read more at news.netcraft.com ...
TOPICS: Business/Economy; News/Current Events; Technical
KEYWORDS: browsers; computersecurity; firefox; gateslapdog; iuseamacsoiambetter; kneepads; littleprecious; lowqualitycrap; marrymebill; microsoft; microsoftastroturf; mskneepadbrigade; netscape; paidshill; redmondianrobots; redmondpayroll; redmondstooge; safari; trollfromredmond; wontyoumarrymebill
Navigation: use the links below to view more comments.
first previous 1-20 ... 61-80, 81-100, 101-120 ... 201-213 next last
To: contemplator
I'm a huge fan of Firefox. Much better than Exploder.
I just made the change you suggested; thanks for the tip.
81
posted on
02/07/2005 12:24:25 PM PST
by
Altamira
(Get the UN out of the US, and the US out of the UN!)
To: ThinkDifferent
" However according to several posters on Slashdot, that setting isn't saved once you quit and relaunch Firefox."
These people are wrong; I just tested this in response to your post.
82
posted on
02/07/2005 12:27:25 PM PST
by
Altamira
(Get the UN out of the US, and the US out of the UN!)
To: TheOtherOne
Hey, thanks for the fix!
Implemented.
83
posted on
02/07/2005 12:28:42 PM PST
by
akorahil
(MSM is RIP)
To: Altamira
It's pretty funny: every time Kweezy puts up one of these let's-prop-up-InternetExploder-a-little-while-longer threads, more people discover and switch to Firefox.
You're not helping your boss Bill, Kweezy.
84
posted on
02/07/2005 12:29:27 PM PST
by
Hank Rearden
(Never allow anyone who could only get a government job attempt to tell you how to run your life.)
To: contemplator
From the above referenced article - "...The attack can be disabled in Firefox and Mozilla by setting 'network.enableIDN' to false in the browser's configuration (enter about:config in the address bar to access the configuration fucntions). " Explain that to the average computer 'tard who barely knows how to turn the pc on and off let alone configure a program.
To: ThinkDifferent
Right. If I looked down at the bar at the bottom of the screen, and it said paypal.com, and I went up at the address bar and it said paypal.com, I would think the site legit.
In the past, it was easy to spot a spoofed site, as it would redirect you to a page in which you could clearly see it was not where it supposedly was taking now.
Well, not anymore....will be checking the code if that crap happens.
86
posted on
02/07/2005 12:31:33 PM PST
by
rwfromkansas
("War is an ugly thing, but...the decayed feeling...which thinks nothing worth war, is worse." -Mill)
Comment #87 Removed by Moderator
To: KwasiOwusu
I have an idea! Let's start catching the booger-eating, snorting, chat room, "tech-savvy" mouth-breathers who instigate viruses, spoofing, spyware, etc. -- and begin sentencing them to lengthy prison terms for the amount of damage and general trouble they cause in this world!!!
Once one or two get their sentences publicized - I bet this crap would slow to a snail's pace, if not halt altogether.
Of course, many of them are the same geeks who develop new technology that serves actual valuable purposes....but it sure would drive the point home, wouldn't it?
88
posted on
02/07/2005 12:36:13 PM PST
by
Don Simmons
(Annoy a liberal: Work hard; Prosper; Be Happy.)
To: contemplator
89
posted on
02/07/2005 12:39:26 PM PST
by
ChefKeith
(Apply here to be added to the NASCAR Ping List, Daytona is comming soon...)
To: Don Simmons
How about we get one of these crap weasels, tie him spreadeagle to the hood of a car and drive around the country charging $5 apiece to kick him in the nuts?
90
posted on
02/07/2005 12:39:56 PM PST
by
Doohickey
("This is a hard and dirty war, but when it's over, nothing will ever be too difficult again.”)
To: Hank Rearden
"It's pretty funny: every time Kweezy puts up one of these let's-prop-up-InternetExploder-a-little-while-longer threads, more people discover and switch to Firefox"
Firefox : 5% and springing security holes faster than a Michael Moore "documentary" springs falsehoods.
IE : approx 90%.
'Nuff said
To: Doohickey
Damn - I like the way you think!!!!
92
posted on
02/07/2005 12:42:08 PM PST
by
Don Simmons
(Annoy a liberal: Work hard; Prosper; Be Happy.)
To: PetroniusMaximus
LMAO!
93
posted on
02/07/2005 12:42:39 PM PST
by
Viking2002
(Let's get the Insurrection started, already..............)
To: KwasiOwusu
Every time you pull those numbers out of your . . . . ummmm . . . hat, the IE number is smaller and the Firefox (which Rocks) number is bigger.
Keep it up!
94
posted on
02/07/2005 12:42:44 PM PST
by
Hank Rearden
(Never allow anyone who could only get a government job attempt to tell you how to run your life.)
To: Hank Rearden
"IE number is smaller and the Firefox (which Rocks) number is bigger."
Ummm .. Firefox still 5%.
Your shill hasn't still made any difference to it.
To: contemplator
BUMP to do this to my home computer as well.
96
posted on
02/07/2005 12:45:10 PM PST
by
RobRoy
(They're trying to find themselves an audience. Their deductions need applause - Peter Gabriel)
To: KwasiOwusu
Well... hello Mr. Gates... didn't know you were a Freeper.
To: WestCoastGal; NormsRevenge; glock rocks; steveegg; tubebender; GRRRRR
98
posted on
02/07/2005 12:46:00 PM PST
by
ChefKeith
(Apply here to be added to the NASCAR Ping List, Daytona is comming soon...)
To: KwasiOwusu
Look around this thread, Kweezy. Or any Firefox thread.
Note the vox populi.
IE is done.
99
posted on
02/07/2005 12:46:13 PM PST
by
Hank Rearden
(Never allow anyone who could only get a government job attempt to tell you how to run your life.)
To: TruBluKentuckian
"Well... hello Mr. Gates... didn't know you were a Freeper."
Hey Linus, or is it Me Raymond?
Still shilling for your copied open source crap are we?
Navigation: use the links below to view more comments.
first previous 1-20 ... 61-80, 81-100, 101-120 ... 201-213 next last
Disclaimer:
Opinions posted on Free Republic are those of the individual
posters and do not necessarily represent the opinion of Free Republic or its
management. All materials posted herein are protected by copyright law and the
exemption for fair use of copyrighted works.
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson