Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Hackers Quickly Target Newly Disclosed Microsoft Flaw
TechWeb - InternetWeek.com ^ | February 10, 2005 | Gregg Keizer

Posted on 02/10/2005 7:31:00 PM PST by Eagle9

click here to read article


Navigation: use the links below to view more comments.
first previous 1-2021-28 last
To: B Knotts

If it's a FireFox flaw it doesn't count, huh. I see. Well I'd rather have a browser that waits to get it right that to use a browser like FireFox that implemented it willy-nilly giving no thought to the security implications. Did they even think to test this first?

21 posted on 02/10/2005 9:23:51 PM PST by yellowhammer
[ Post Reply | Private Reply | To 20 | View Replies]

To: yellowhammer

It's not a Firefox flaw, though. I don't even use Firefox, mostly.

It's a flaw in the IDN standard, sort of. It's really a flaw in Unicode, if you think about it. The problem is that multiple Unicode codes can refer to identical or nearly identical glyphs.

It's more of a social engineering thing, than a software flaw.

The same trick could be pulled using any "secure" application which allows Unicode characters in hostnames.


22 posted on 02/10/2005 9:30:04 PM PST by B Knotts
[ Post Reply | Private Reply | To 21 | View Replies]

To: yellowhammer
If it's a FireFox flaw it doesn't count, huh. I see.

But it's not a browser flaw. Even Internet Explorer can be spoofed with look-alike characters in a URL - like substituting the number 0 (zero) for the letter "0".

For instance - WWW.MlCR0S0FT.COM is not the same as WWW.MICROSOFT.COM. But people can be fooled because of the the visual similarity. Can you spot the differences?

23 posted on 02/10/2005 10:37:55 PM PST by HAL9000
[ Post Reply | Private Reply | To 21 | View Replies]

To: yellowhammer
IE with an IDN plugin will act the exact same way. And on Linux this bug does not work (at least for the example page used in the article). This is a problem with teh way Mac's and Windows draw IDN.

I will fault the firefox developers for having it on by default..

24 posted on 02/11/2005 5:21:43 AM PST by N3WBI3
[ Post Reply | Private Reply | To 21 | View Replies]

To: Boundless
When did MS implement PNG support in Windows?

Word 2000 Supported PNGs. No question about it though, they screwed the pooch on this one. How you get from interpreting a graphic format into running arbitrary code in the local zone is just mind boggling to me.

25 posted on 02/11/2005 6:21:15 AM PST by Malsua
[ Post Reply | Private Reply | To 19 | View Replies]

To: Malsua
How you get from interpreting a graphic format into running arbitrary code in the local zone is just mind boggling to me.

Get a clue. This sort of problem is widespread and doesn't merely affect MS.
26 posted on 02/11/2005 6:03:29 PM PST by Bush2000
[ Post Reply | Private Reply | To 25 | View Replies]

To: Bush2000
Get a clue

Thanks for the advice. I'm a complete feeb. In fact, I have to wear a bib since I'm such a slobbering idiot. Gonna run right out and get me a clue soon as I can.

27 posted on 02/11/2005 6:47:44 PM PST by Malsua
[ Post Reply | Private Reply | To 26 | View Replies]

To: Malsua

No problem. I'm here to help. Have a nice weekend. :)


28 posted on 02/11/2005 7:26:26 PM PST by Bush2000
[ Post Reply | Private Reply | To 27 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-28 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson