Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Non-Microsoft Browsers Have Spoofing Flaw
Netcraft ^ | 2/7/2005 | Netcraft

Posted on 02/07/2005 11:29:30 AM PST by KwasiOwusu

All non-Microsoft browers include a flaw that allows URL spoofing using Unicode characters, which can be exploited by phishing scams seeking to steal login information for online banking accounts. The spoofing flaw, which is demonstrated on the web site of the Shmoo Group, works in the Firefox, Mozilla and Opera browsers, as well as the Safari browser for Macs.
The spoof exploits flaws in how the browsers interpret Unicode characters. A link using Unicode characters to replace the letter "a" in "Paypal" will display as www.paypal.com in the browser, but send users to www.xn--pypal-4ve.com - which then displays "www.paypal.com" in its address bar. A similar spoof works on SSL-enabled URLs (https) commonly used on banking and e-commerce sites.

Unicode is a broader character set that includes non-English characters as well as symbols, which is being used on the Internet to support Internationalized Domain Names (IDN). The affected browsers support IDN, while Microsoft's Internet Explorer does not.

(Excerpt) Read more at news.netcraft.com ...


TOPICS: Business/Economy; News/Current Events; Technical
KEYWORDS: browsers; computersecurity; firefox; gateslapdog; iuseamacsoiambetter; kneepads; littleprecious; lowqualitycrap; marrymebill; microsoft; microsoftastroturf; mskneepadbrigade; netscape; paidshill; redmondianrobots; redmondpayroll; redmondstooge; safari; trollfromredmond; wontyoumarrymebill
Navigation: use the links below to view more comments.
first previous 1-20 ... 61-8081-100101-120 ... 201-213 next last
To: contemplator

I'm a huge fan of Firefox. Much better than Exploder.

I just made the change you suggested; thanks for the tip.


81 posted on 02/07/2005 12:24:25 PM PST by Altamira (Get the UN out of the US, and the US out of the UN!)
[ Post Reply | Private Reply | To 5 | View Replies]

To: ThinkDifferent

" However according to several posters on Slashdot, that setting isn't saved once you quit and relaunch Firefox."

These people are wrong; I just tested this in response to your post.


82 posted on 02/07/2005 12:27:25 PM PST by Altamira (Get the UN out of the US, and the US out of the UN!)
[ Post Reply | Private Reply | To 25 | View Replies]

To: TheOtherOne
Hey, thanks for the fix!

Implemented.

83 posted on 02/07/2005 12:28:42 PM PST by akorahil (MSM is RIP)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Altamira
It's pretty funny: every time Kweezy puts up one of these let's-prop-up-InternetExploder-a-little-while-longer threads, more people discover and switch to Firefox.

You're not helping your boss Bill, Kweezy.

84 posted on 02/07/2005 12:29:27 PM PST by Hank Rearden (Never allow anyone who could only get a government job attempt to tell you how to run your life.)
[ Post Reply | Private Reply | To 81 | View Replies]

To: contemplator
From the above referenced article - "...The attack can be disabled in Firefox and Mozilla by setting 'network.enableIDN' to false in the browser's configuration (enter about:config in the address bar to access the configuration fucntions). "

Explain that to the average computer 'tard who barely knows how to turn the pc on and off let alone configure a program.

85 posted on 02/07/2005 12:30:15 PM PST by Labyrinthos
[ Post Reply | Private Reply | To 5 | View Replies]

To: ThinkDifferent

Right. If I looked down at the bar at the bottom of the screen, and it said paypal.com, and I went up at the address bar and it said paypal.com, I would think the site legit.

In the past, it was easy to spot a spoofed site, as it would redirect you to a page in which you could clearly see it was not where it supposedly was taking now.

Well, not anymore....will be checking the code if that crap happens.


86 posted on 02/07/2005 12:31:33 PM PST by rwfromkansas ("War is an ugly thing, but...the decayed feeling...which thinks nothing worth war, is worse." -Mill)
[ Post Reply | Private Reply | To 35 | View Replies]

Comment #87 Removed by Moderator

To: KwasiOwusu

I have an idea! Let's start catching the booger-eating, snorting, chat room, "tech-savvy" mouth-breathers who instigate viruses, spoofing, spyware, etc. -- and begin sentencing them to lengthy prison terms for the amount of damage and general trouble they cause in this world!!!

Once one or two get their sentences publicized - I bet this crap would slow to a snail's pace, if not halt altogether.

Of course, many of them are the same geeks who develop new technology that serves actual valuable purposes....but it sure would drive the point home, wouldn't it?


88 posted on 02/07/2005 12:36:13 PM PST by Don Simmons (Annoy a liberal: Work hard; Prosper; Be Happy.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: contemplator

Thank You!


89 posted on 02/07/2005 12:39:26 PM PST by ChefKeith (Apply here to be added to the NASCAR Ping List, Daytona is comming soon...)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Don Simmons

How about we get one of these crap weasels, tie him spreadeagle to the hood of a car and drive around the country charging $5 apiece to kick him in the nuts?


90 posted on 02/07/2005 12:39:56 PM PST by Doohickey ("This is a hard and dirty war, but when it's over, nothing will ever be too difficult again.”)
[ Post Reply | Private Reply | To 88 | View Replies]

To: Hank Rearden
"It's pretty funny: every time Kweezy puts up one of these let's-prop-up-InternetExploder-a-little-while-longer threads, more people discover and switch to Firefox"

Firefox : 5% and springing security holes faster than a Michael Moore "documentary" springs falsehoods.
IE : approx 90%.
'Nuff said
91 posted on 02/07/2005 12:40:23 PM PST by KwasiOwusu
[ Post Reply | Private Reply | To 84 | View Replies]

To: Doohickey

Damn - I like the way you think!!!!


92 posted on 02/07/2005 12:42:08 PM PST by Don Simmons (Annoy a liberal: Work hard; Prosper; Be Happy.)
[ Post Reply | Private Reply | To 90 | View Replies]

To: PetroniusMaximus
LMAO!


93 posted on 02/07/2005 12:42:39 PM PST by Viking2002 (Let's get the Insurrection started, already..............)
[ Post Reply | Private Reply | To 9 | View Replies]

To: KwasiOwusu
Every time you pull those numbers out of your . . . . ummmm . . . hat, the IE number is smaller and the Firefox (which Rocks) number is bigger.

Keep it up!

94 posted on 02/07/2005 12:42:44 PM PST by Hank Rearden (Never allow anyone who could only get a government job attempt to tell you how to run your life.)
[ Post Reply | Private Reply | To 91 | View Replies]

To: Hank Rearden
"IE number is smaller and the Firefox (which Rocks) number is bigger."

Ummm .. Firefox still 5%.
Your shill hasn't still made any difference to it.
95 posted on 02/07/2005 12:44:14 PM PST by KwasiOwusu
[ Post Reply | Private Reply | To 94 | View Replies]

To: contemplator

BUMP to do this to my home computer as well.


96 posted on 02/07/2005 12:45:10 PM PST by RobRoy (They're trying to find themselves an audience. Their deductions need applause - Peter Gabriel)
[ Post Reply | Private Reply | To 5 | View Replies]

To: KwasiOwusu

Well... hello Mr. Gates... didn't know you were a Freeper.


97 posted on 02/07/2005 12:45:29 PM PST by TruBluKentuckian
[ Post Reply | Private Reply | To 95 | View Replies]

To: WestCoastGal; NormsRevenge; glock rocks; steveegg; tubebender; GRRRRR

PING!


98 posted on 02/07/2005 12:46:00 PM PST by ChefKeith (Apply here to be added to the NASCAR Ping List, Daytona is comming soon...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: KwasiOwusu
Look around this thread, Kweezy. Or any Firefox thread.

Note the vox populi.

IE is done.

99 posted on 02/07/2005 12:46:13 PM PST by Hank Rearden (Never allow anyone who could only get a government job attempt to tell you how to run your life.)
[ Post Reply | Private Reply | To 95 | View Replies]

To: TruBluKentuckian
"Well... hello Mr. Gates... didn't know you were a Freeper."

Hey Linus, or is it Me Raymond?
Still shilling for your copied open source crap are we?
100 posted on 02/07/2005 12:47:14 PM PST by KwasiOwusu
[ Post Reply | Private Reply | To 97 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-20 ... 61-8081-100101-120 ... 201-213 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson