danceboy: (Default)
[personal profile] danceboy
Hey all, if anyone is using firefox, please check this out. It turns out that due to Firefox correctly implementing a flawed standard, it is vulnerable to certain spoofing attacks. They've come up with a fix pretty quickly, and it's yet another reason to get AdBlock...

I do not believe that any attacks were found using this, it looks like some people discovered the problem and then announced it.

You can disable the feature -- easier fix

Date: 2005-02-22 03:36 am (UTC)
From: [identity profile] vectorvillain.livejournal.com
Go to the address bar, and type "about:config". Scroll down to "Network.enableIDN", and double click on it.

This disables the flawed standard. It isn't all that likely that most people use IDN, so i souldn't impact anything.

From you friendly neighborhood IT security wonk.

Re: You can disable the feature -- easier fix

Date: 2005-02-22 05:27 pm (UTC)
From: [identity profile] danceboy.livejournal.com
I dunno, according to bugzilla and mozillazine, that only sticks around until you restart, and the standard way to fix that (editing the compreg.dat directly) only sticks around until you install a new extension (when it gets over-written).

It seems that whoever added IDN to the about:config neglected to add it to the serializer in time for the 1.0 branch. It had already been fixed before the exploit came out, but they haven't released a new version yet.

Regarding IDN itself, I think it's a bad idea to come up with a standard that allows people to think that they're visiting one site, and actually bring them to another. They forgot the "How will evil people try to abuse this?" test.

Profile

danceboy: (Default)
danceboy

October 2017

S M T W T F S
1234567
8910111213 14
15161718192021
22 232425262728
293031    

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Feb. 25th, 2026 08:10 pm
Powered by Dreamwidth Studios