Flaw in Firefox
Discussion
For your info guys:
There's a significant bug in the Firefox web browser which allows a malicious site to pose as a genuine one - complete with a valid-looking URL that even stands up to scrutiny when you right click the page and select the 'View Page Info' command; it is possible to fix the vulnerability (possibly only temporarily) by changing a setting in Firefox as follows:
First, to see if your version has the problem, go to this website: www.shmoo.com/idn/ and choose one of the links shown to 'Paypal' (these are demonstration links and won't take you anywhere malicious) If you click on the links and you see the URL presented as 'www.paypal.com' your system is vulnerable to the bug.
To fix this in Firefox/Mozilla
1. type "about:config" in your address bar.
2. type "idn" in the Filter
3. set network.enableIDN to false (double-click 'true' to do this)
Now go back to www.shmoo.com/idn/ and try the "paypal" links again. You should get and Alert box that says "www.paypal.com could not be found."
Note that this exploit doesn't affect Internet Explorer unless you've installed an idn plugin.
We will look out for an update announcement from Mozilla.
There's a significant bug in the Firefox web browser which allows a malicious site to pose as a genuine one - complete with a valid-looking URL that even stands up to scrutiny when you right click the page and select the 'View Page Info' command; it is possible to fix the vulnerability (possibly only temporarily) by changing a setting in Firefox as follows:
First, to see if your version has the problem, go to this website: www.shmoo.com/idn/ and choose one of the links shown to 'Paypal' (these are demonstration links and won't take you anywhere malicious) If you click on the links and you see the URL presented as 'www.paypal.com' your system is vulnerable to the bug.
To fix this in Firefox/Mozilla
1. type "about:config" in your address bar.
2. type "idn" in the Filter
3. set network.enableIDN to false (double-click 'true' to do this)
Now go back to www.shmoo.com/idn/ and try the "paypal" links again. You should get and Alert box that says "www.paypal.com could not be found."
Note that this exploit doesn't affect Internet Explorer unless you've installed an idn plugin.
We will look out for an update announcement from Mozilla.
Seems a legit problem...
http://news.com.com/Firefox+flaw+raises+phishing+fears/2100-1002_3-5517149.html
http://news.com.com/Firefox+flaw+raises+phishing+fears/2100-1002_3-5517149.html
Thread below....
www.pistonheads.com/gassing/topic.asp?t=154622&f=95&h=0
IE looks safe. Mozilla/FF/Opera are affected.
www.pistonheads.com/gassing/topic.asp?t=154622&f=95&h=0
IE looks safe. Mozilla/FF/Opera are affected.
Sorry Ted not a clue... just copied you guys in from a warning from the IT Department of the Open University, as I know may of you use FIREFOX.
more details on IDN here www.shmoo.com/idn/homograph.txt
If your not getting the message after applying the fix, I can only assume you are not using a version which has this vulnerability.
Alan
more details on IDN here www.shmoo.com/idn/homograph.txt
If your not getting the message after applying the fix, I can only assume you are not using a version which has this vulnerability.
Alan
joospeed said:
hmm. so doing the change to *false* doesn't actually cure it then? cos the link in the other thread sends you to the spoof page whilst still displaying the paypal address
You mean the http://secunia.com/multiple_browsers_idn_spoofing_test ?
It worked for me had the page appear set to true, set it to false and got a page cannot be found popup. Both test worked too.
Apparently it's caused by a faulty implementation of International Domain Name support. IE doesn't support this - yet, although according to www.it-analysis.com/article.php?articleid=12557&SESSID=bab29ef450d9f77bca15a4c8c633ee65 it has other vulnerabilities which have a similar effect.
FourWheelDrift said:
joospeed said:
hmm. so doing the change to *false* doesn't actually cure it then? cos the link in the other thread sends you to the spoof page whilst still displaying the paypal address
You mean the http://secunia.com/multiple_browsers_idn_spoofing_test ?
It worked for me had the page appear set to true, set it to false and got a page cannot be found popup. Both test worked too.
yeh the secunia one worked ok, but ther's another test page somewhere and it didn't work on that .. it's in the other thread on this subject.
further info:
This is an amended bulletin following a number of questions we've received
- even if you succeed in making the change proposed below, it won't go on working after you close and re-open Firefox or Mozilla. An extra 'helpful' URL at the bottom of this email does explain a rather unsettling technical procedure that you can try to fix it permanently. We do expect some further notices about this flaw soon and an update from Mozilla at some point. We can take no responsibility for the advice given by third-parties below, and offer the 'suggested fix' as one possibility to try.
----
There's a significant bug in the Firefox web browser which allows a malicious site to pose as a genuine one - complete with a valid-looking URL that even stands up to scrutiny when you right click the page and select the 'View Page Info' command; it is possible to fix the vulnerability (possibly only temporarily) by changing a setting in Firefox as follows:
First, to see if your version has the problem, go to this website: www.shmoo.com/idn/ and choose one of the links shown to 'Paypal' (these are demonstration links and won't take you anywhere malicious) If you click on the links and you see the URL presented as 'www.paypal.com' and the word 'meow' on the page, your system is vulnerable to the bug. If you use the [View][Page Source] command, you can see the underlying HTML instructions.
To fix this for the current session in Firefox/Mozilla
1. type " about:config " (no quotes) in your address bar and press [Enter]. 2. type " idn " (no quotes) in the Filter bar which appears automatically and press [Enter] 3. set network.enableIDN to false (double-click 'true' to do this)
Now go back to www.shmoo.com/idn/ and try the "paypal" links again. You should get and Alert box that says "www.paypal.com could not be found." However, these settings revert when you close the browser and reopen it again.
Note that this exploit doesn't affect Internet Explorer unless you've installed an idn plugin.
We will look out for an update announcement from Mozilla.
-------------------------------------------------------------------------------------------------------------------
Here are some useful weblinks that relate to the message above.
Shmoo: www.shmoo.com/idn/homograph.txt
boingboing: www.boingboing.net/2005/02/06/shmoo_group_exploit_.html
The Register: www.theregister.co.uk/2005/02/07/browsers_idn_spoofing/
Information Week: www.informationweek.com/story/showArticle.jhtml?articleID=59301679
PC World: www.pcworld.idg.com.au/index.php/id;1052848683;fp;2;fpid;1
Suggested fix: http://users.tns.net/~skingery/weblog/2005/02/permanent-fix-for-shmoo-group-exploit.html
-------------------------------------------------------------------------------------------------------------------
This is an amended bulletin following a number of questions we've received
- even if you succeed in making the change proposed below, it won't go on working after you close and re-open Firefox or Mozilla. An extra 'helpful' URL at the bottom of this email does explain a rather unsettling technical procedure that you can try to fix it permanently. We do expect some further notices about this flaw soon and an update from Mozilla at some point. We can take no responsibility for the advice given by third-parties below, and offer the 'suggested fix' as one possibility to try.
----
There's a significant bug in the Firefox web browser which allows a malicious site to pose as a genuine one - complete with a valid-looking URL that even stands up to scrutiny when you right click the page and select the 'View Page Info' command; it is possible to fix the vulnerability (possibly only temporarily) by changing a setting in Firefox as follows:
First, to see if your version has the problem, go to this website: www.shmoo.com/idn/ and choose one of the links shown to 'Paypal' (these are demonstration links and won't take you anywhere malicious) If you click on the links and you see the URL presented as 'www.paypal.com' and the word 'meow' on the page, your system is vulnerable to the bug. If you use the [View][Page Source] command, you can see the underlying HTML instructions.
To fix this for the current session in Firefox/Mozilla
1. type " about:config " (no quotes) in your address bar and press [Enter]. 2. type " idn " (no quotes) in the Filter bar which appears automatically and press [Enter] 3. set network.enableIDN to false (double-click 'true' to do this)
Now go back to www.shmoo.com/idn/ and try the "paypal" links again. You should get and Alert box that says "www.paypal.com could not be found." However, these settings revert when you close the browser and reopen it again.
Note that this exploit doesn't affect Internet Explorer unless you've installed an idn plugin.
We will look out for an update announcement from Mozilla.
-------------------------------------------------------------------------------------------------------------------
Here are some useful weblinks that relate to the message above.
Shmoo: www.shmoo.com/idn/homograph.txt
boingboing: www.boingboing.net/2005/02/06/shmoo_group_exploit_.html
The Register: www.theregister.co.uk/2005/02/07/browsers_idn_spoofing/
Information Week: www.informationweek.com/story/showArticle.jhtml?articleID=59301679
PC World: www.pcworld.idg.com.au/index.php/id;1052848683;fp;2;fpid;1
Suggested fix: http://users.tns.net/~skingery/weblog/2005/02/permanent-fix-for-shmoo-group-exploit.html
-------------------------------------------------------------------------------------------------------------------
I did the change from true to false on the IDN setting, logged off closed Firefox down. Just rebooted and it's still set to false for me so it hasn't reset itself. How odd.
Maybe it depends on the type of Firefox version you are running and your upgrade path. I went from 0.8 to 0.9 to 1.0PreRelease and now V1.0 full version.
Maybe it depends on the type of Firefox version you are running and your upgrade path. I went from 0.8 to 0.9 to 1.0PreRelease and now V1.0 full version.
Gassing Station | Computers, Gadgets & Stuff | Top of Page | What's New | My Stuff






