Flaw in Firefox
Author
Discussion

amcdee

Original Poster:

51 posts

266 months

Tuesday 8th February 2005
quotequote all
For your info guys:

There's a significant bug in the Firefox web browser which allows a malicious site to pose as a genuine one - complete with a valid-looking URL that even stands up to scrutiny when you right click the page and select the 'View Page Info' command; it is possible to fix the vulnerability (possibly only temporarily) by changing a setting in Firefox as follows:

First, to see if your version has the problem, go to this website: www.shmoo.com/idn/ and choose one of the links shown to 'Paypal' (these are demonstration links and won't take you anywhere malicious) If you click on the links and you see the URL presented as 'www.paypal.com' your system is vulnerable to the bug.

To fix this in Firefox/Mozilla
1. type "about:config" in your address bar.
2. type "idn" in the Filter
3. set network.enableIDN to false (double-click 'true' to do this)

Now go back to www.shmoo.com/idn/ and try the "paypal" links again. You should get and Alert box that says "www.paypal.com could not be found."

Note that this exploit doesn't affect Internet Explorer unless you've installed an idn plugin.

We will look out for an update announcement from Mozilla.

PetrolTed

34,468 posts

333 months

Tuesday 8th February 2005
quotequote all
My enableIDN is already set to false and yet the links are fooling the browser.

What's IDN?

joospeed

4,473 posts

308 months

Tuesday 8th February 2005
quotequote all
Worked for me. dunno what the heck you're on about or how all this fiddling changes stuff, but you have an honest face so I'll trust is for the better

size13

2,033 posts

287 months

Mr E

23,066 posts

289 months

Tuesday 8th February 2005
quotequote all
Thread below....

www.pistonheads.com/gassing/topic.asp?t=154622&f=95&h=0

IE looks safe. Mozilla/FF/Opera are affected.

amcdee

Original Poster:

51 posts

266 months

Tuesday 8th February 2005
quotequote all
Sorry Ted not a clue... just copied you guys in from a warning from the IT Department of the Open University, as I know may of you use FIREFOX.

more details on IDN here www.shmoo.com/idn/homograph.txt

If your not getting the message after applying the fix, I can only assume you are not using a version which has this vulnerability.

Alan

joospeed

4,473 posts

308 months

Tuesday 8th February 2005
quotequote all
hmm. so doing the change to *false* doesn't actually cure it then? cos the link in the other thread sends you to the spoof page whilst still displaying the paypal address

FourWheelDrift

92,308 posts

314 months

Tuesday 8th February 2005
quotequote all
joospeed said:
hmm. so doing the change to *false* doesn't actually cure it then? cos the link in the other thread sends you to the spoof page whilst still displaying the paypal address


You mean the http://secunia.com/multiple_browsers_idn_spoofing_test ?

It worked for me had the page appear set to true, set it to false and got a page cannot be found popup. Both test worked too.

GreenV8S

31,021 posts

314 months

Tuesday 8th February 2005
quotequote all
Apparently it's caused by a faulty implementation of International Domain Name support. IE doesn't support this - yet, although according to www.it-analysis.com/article.php?articleid=12557&SESSID=bab29ef450d9f77bca15a4c8c633ee65 it has other vulnerabilities which have a similar effect.

joospeed

4,473 posts

308 months

Tuesday 8th February 2005
quotequote all
FourWheelDrift said:

joospeed said:
hmm. so doing the change to *false* doesn't actually cure it then? cos the link in the other thread sends you to the spoof page whilst still displaying the paypal address



You mean the http://secunia.com/multiple_browsers_idn_spoofing_test ?

It worked for me had the page appear set to true, set it to false and got a page cannot be found popup. Both test worked too.


yeh the secunia one worked ok, but ther's another test page somewhere and it didn't work on that .. it's in the other thread on this subject.

amcdee

Original Poster:

51 posts

266 months

Tuesday 8th February 2005
quotequote all
further info:

This is an amended bulletin following a number of questions we've received
- even if you succeed in making the change proposed below, it won't go on working after you close and re-open Firefox or Mozilla. An extra 'helpful' URL at the bottom of this email does explain a rather unsettling technical procedure that you can try to fix it permanently. We do expect some further notices about this flaw soon and an update from Mozilla at some point. We can take no responsibility for the advice given by third-parties below, and offer the 'suggested fix' as one possibility to try.
----
There's a significant bug in the Firefox web browser which allows a malicious site to pose as a genuine one - complete with a valid-looking URL that even stands up to scrutiny when you right click the page and select the 'View Page Info' command; it is possible to fix the vulnerability (possibly only temporarily) by changing a setting in Firefox as follows:

First, to see if your version has the problem, go to this website: www.shmoo.com/idn/ and choose one of the links shown to 'Paypal' (these are demonstration links and won't take you anywhere malicious) If you click on the links and you see the URL presented as 'www.paypal.com' and the word 'meow' on the page, your system is vulnerable to the bug. If you use the [View][Page Source] command, you can see the underlying HTML instructions.

To fix this for the current session in Firefox/Mozilla
1. type " about:config " (no quotes) in your address bar and press [Enter]. 2. type " idn " (no quotes) in the Filter bar which appears automatically and press [Enter] 3. set network.enableIDN to false (double-click 'true' to do this)

Now go back to www.shmoo.com/idn/ and try the "paypal" links again. You should get and Alert box that says "www.paypal.com could not be found." However, these settings revert when you close the browser and reopen it again.

Note that this exploit doesn't affect Internet Explorer unless you've installed an idn plugin.

We will look out for an update announcement from Mozilla.
-------------------------------------------------------------------------------------------------------------------

Here are some useful weblinks that relate to the message above.

Shmoo: www.shmoo.com/idn/homograph.txt
boingboing: www.boingboing.net/2005/02/06/shmoo_group_exploit_.html
The Register: www.theregister.co.uk/2005/02/07/browsers_idn_spoofing/
Information Week: www.informationweek.com/story/showArticle.jhtml?articleID=59301679
PC World: www.pcworld.idg.com.au/index.php/id;1052848683;fp;2;fpid;1
Suggested fix: http://users.tns.net/~skingery/weblog/2005/02/permanent-fix-for-shmoo-group-exploit.html
-------------------------------------------------------------------------------------------------------------------

Mr E

23,066 posts

289 months

Tuesday 8th February 2005
quotequote all
Meh, my earlier thread has been killed.



stumartin

1,706 posts

267 months

Tuesday 8th February 2005
quotequote all
So essentially, there's little that can be done on a permanent basis (unless you keep Firefox open 24/7) until Mozilla rectify the flaw with an update?

And so, unless you want to keep playing around with that setting each time you open ff, there's not much point and just 'be wary'?

FourWheelDrift

92,308 posts

314 months

Tuesday 8th February 2005
quotequote all
I did the change from true to false on the IDN setting, logged off closed Firefox down. Just rebooted and it's still set to false for me so it hasn't reset itself. How odd.

Maybe it depends on the type of Firefox version you are running and your upgrade path. I went from 0.8 to 0.9 to 1.0PreRelease and now V1.0 full version.

size13

2,033 posts

287 months

Wednesday 9th February 2005
quotequote all
Mine is still false after a reboot too. I'm on v1