Browser Hack, Firefox users beware

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

Post Reply
User avatar
Plekhanov
Sith Marauder
Posts: 3991
Joined: 2004-04-01 11:09pm
Location: Mercia

Browser Hack, Firefox users beware

Post by Plekhanov »

www.shmoo.com/idn

Who'd have thought it a hack that doesn't affect microsoft stuff.
User avatar
Sharp-kun
Sith Devotee
Posts: 2993
Joined: 2003-09-10 05:12am
Location: Glasgow, Scotland

Re: Browser Hack, Firefox users beware

Post by Sharp-kun »

Plekhanov wrote: Who'd have thought it a hack that doesn't affect microsoft stuff.
There's a reasonable amount, they just tend not to get publicised as much.
User avatar
Darth Wong
Sith Lord
Sith Lord
Posts: 70028
Joined: 2002-07-03 12:25am
Location: Toronto, Canada
Contact:

Post by Darth Wong »

Ironically, this is precisely because IE has been so badly neglected. Since it doesn't support some of the newer encoding standards, and this hack relies on abuse of one of those newer encoding standards, it doesn't work on IE. It's a bit like saying that a cell-phone hack doesn't work on a land-line.
Image
"It's not evil for God to do it. Or for someone to do it at God's command."- Jonathan Boyd on baby-killing

"you guys are fascinated with the use of those "rules of logic" to the extent that you don't really want to discussus anything."- GC

"I do not believe Russian Roulette is a stupid act" - Embracer of Darkness

"Viagra commercials appear to save lives" - tharkûn on US health care.

http://www.stardestroyer.net/Mike/RantMode/Blurbs.html
User avatar
Crayz9000
Sith Apprentice
Posts: 7329
Joined: 2002-07-03 06:39pm
Location: Improbably superpositioned
Contact:

Post by Crayz9000 »

The fix for Firefox and other Mozilla-based browsers is trivially easy.

Simply go to about:config, and look for network.enableIDN. Set its value to false.

That's it. No more spoofing via IDN.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
User avatar
Zac Naloen
Sith Acolyte
Posts: 5488
Joined: 2003-07-24 04:32pm
Location: United Kingdom

Post by Zac Naloen »

Crayz9000 wrote:The fix for Firefox and other Mozilla-based browsers is trivially easy.

Simply go to about:config, and look for network.enableIDN. Set its value to false.

That's it. No more spoofing via IDN.
for us idiots... how do you do that.. exactly...?

:D
Image
Member of the Unremarkables
Just because you're god, it doesn't mean you can treat people that way : - My girlfriend
Evil Brit Conspiracy - Insignificant guy
User avatar
Drooling Iguana
Sith Marauder
Posts: 4975
Joined: 2003-05-13 01:07am
Location: Sector ZZ9 Plural Z Alpha

Post by Drooling Iguana »

Zac Naloen wrote:
Crayz9000 wrote:The fix for Firefox and other Mozilla-based browsers is trivially easy.

Simply go to about:config, and look for network.enableIDN. Set its value to false.

That's it. No more spoofing via IDN.
for us idiots... how do you do that.. exactly...?

:D
Exactly what he said. Type "about:config" in the URL bar, scroll down until you find network.enableIDN and set it to false.
Image
"Stop! No one can survive these deadly rays!"
"These deadly rays will be your death!"
- Thor and Akton, Starcrash

"Before man reaches the moon your mail will be delivered within hours from New York to California, to England, to India or to Australia by guided missiles.... We stand on the threshold of rocket mail."
- Arthur Summerfield, US Postmaster General 1953 - 1961
User avatar
Faram
Bastard Operator from Hell
Posts: 5271
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Post by Faram »

Thanx for the tip Crayz9000

Zac Naloen here is a screenshot for you.

Image
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
Medic
Sith Devotee
Posts: 2632
Joined: 2004-12-31 01:51pm
Location: Deep South

Post by Medic »

And with that an exploit is PWN3D in the face. Goodbye Internet Explorer, you crazy insecure bitch.

(edit: I just recently upgraded to Mozillafox, as I'm calling it)
User avatar
Lucifer
Idiotic Conspiracy Nut
Posts: 134
Joined: 2005-01-28 06:47pm
Location: Canada
Contact:

Post by Lucifer »

I have both Netscape and Firefox on OSX, and they're remarkably similar. However, I don't know if Netscape has the same IDN problems as Firefox.
User avatar
Crayz9000
Sith Apprentice
Posts: 7329
Joined: 2002-07-03 06:39pm
Location: Improbably superpositioned
Contact:

Post by Crayz9000 »

Lucifer wrote:I have both Netscape and Firefox on OSX, and they're remarkably similar. However, I don't know if Netscape has the same IDN problems as Firefox.
It's a Mozilla-based browser, so probably yes.

about:config should work if it's Netscape 7, and won't work if it's Netscape 6. Besides, if it's NS6 you should upgrade it due to an older security bug.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
User avatar
LadyTevar
White Mage
White Mage
Posts: 23482
Joined: 2003-02-12 10:59pm

Post by LadyTevar »

Wow... that was easy. Took me only 30 sec.

Thanks!
Image
Nitram, slightly high on cough syrup: Do you know you're beautiful?
Me: Nope, that's why I have you around to tell me.
Nitram: You -are- beautiful. Anyone tries to tell you otherwise kill them.

"A life is like a garden. Perfect moments can be had, but not preserved, except in memory. LLAP" -- Leonard Nimoy, last Tweet
Nieztchean Uber-Amoeba
Sith Devotee
Posts: 3317
Joined: 2004-10-15 08:57pm
Location: Regina Nihilists' Guild Party Headquarters

Post by Nieztchean Uber-Amoeba »

Woah. That took me, like 10 seconds to toggle IDN to false.

FIREFOX FUCKING RULES!!!
User avatar
CelesKnight
Padawan Learner
Posts: 459
Joined: 2003-08-20 11:45pm
Location: USA

Post by CelesKnight »

Are you sure that that solution works?

I set the setting to false, rebooted, cleared the caches, checked that the setting was still false, and the "fake" link still works.

Either:
A) I'm misunderstanding the problem and/or solution
or
B) There may be people here who think they're protected but aren't.

This site gives a "permanent" solution, but I haven't tried it yet.
ASVS Class of 1997
BotM / HAB / KAC
User avatar
Crayz9000
Sith Apprentice
Posts: 7329
Joined: 2002-07-03 06:39pm
Location: Improbably superpositioned
Contact:

Post by Crayz9000 »

... that's quite bizarre. When I first tried it, it prevented the IDN spoofed domain from working. Now (he did modify the link however) it does work.

Following what the guy said in the link you posted, I can see why. It's irritating that changes in about:config don't hold over. Anyway, I have tested the fix that he proposed and I can confirm it does work. But for most people, using the AdBlock extension fix that he gave would probably be easier.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
User avatar
Crayz9000
Sith Apprentice
Posts: 7329
Joined: 2002-07-03 06:39pm
Location: Improbably superpositioned
Contact:

Post by Crayz9000 »

I have another update to add.

If you use vanilla Mozilla, then you can get the MultiZilla extension. Get the latest stable nightly, which is 1.8.x.x. Multizilla now features a "secret" hashing feature for SSL sites that will warn you of a spoofed IDN domain (I tested it -- the regular link still worked as before, but the more dangerous SSL link was noticed by Multizilla...

So if you use vanilla Mozilla, I would use Multizilla until the next version of Mozilla is released sans IDN support.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
darthdavid
Pathetic Attention Whore
Posts: 5470
Joined: 2003-02-17 12:04pm
Location: Bat Country!

Post by darthdavid »

I don't know if it's cause I'm using the debian build of FF but it was set to false by default. :D
User avatar
Crayz9000
Sith Apprentice
Posts: 7329
Joined: 2002-07-03 06:39pm
Location: Improbably superpositioned
Contact:

Post by Crayz9000 »

Test the spoof page again and see if it works. Remember that as above, the network.enableIDN solution doesn't seem to be working properly... I don't know if it's the case for the Debian build.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
Post Reply