Page 1 of 1

Browser Hack, Firefox users beware

Posted: 2005-02-08 10:24am
by Plekhanov
www.shmoo.com/idn

Who'd have thought it a hack that doesn't affect microsoft stuff.

Re: Browser Hack, Firefox users beware

Posted: 2005-02-08 10:32am
by Sharp-kun
Plekhanov wrote: Who'd have thought it a hack that doesn't affect microsoft stuff.
There's a reasonable amount, they just tend not to get publicised as much.

Posted: 2005-02-08 10:47am
by Darth Wong
Ironically, this is precisely because IE has been so badly neglected. Since it doesn't support some of the newer encoding standards, and this hack relies on abuse of one of those newer encoding standards, it doesn't work on IE. It's a bit like saying that a cell-phone hack doesn't work on a land-line.

Posted: 2005-02-08 11:32am
by Crayz9000
The fix for Firefox and other Mozilla-based browsers is trivially easy.

Simply go to about:config, and look for network.enableIDN. Set its value to false.

That's it. No more spoofing via IDN.

Posted: 2005-02-08 05:46pm
by Zac Naloen
Crayz9000 wrote:The fix for Firefox and other Mozilla-based browsers is trivially easy.

Simply go to about:config, and look for network.enableIDN. Set its value to false.

That's it. No more spoofing via IDN.
for us idiots... how do you do that.. exactly...?

:D

Posted: 2005-02-08 06:53pm
by Drooling Iguana
Zac Naloen wrote:
Crayz9000 wrote:The fix for Firefox and other Mozilla-based browsers is trivially easy.

Simply go to about:config, and look for network.enableIDN. Set its value to false.

That's it. No more spoofing via IDN.
for us idiots... how do you do that.. exactly...?

:D
Exactly what he said. Type "about:config" in the URL bar, scroll down until you find network.enableIDN and set it to false.

Posted: 2005-02-09 03:17am
by Faram
Thanx for the tip Crayz9000

Zac Naloen here is a screenshot for you.

Image

Posted: 2005-02-09 05:04am
by Medic
And with that an exploit is PWN3D in the face. Goodbye Internet Explorer, you crazy insecure bitch.

(edit: I just recently upgraded to Mozillafox, as I'm calling it)

Posted: 2005-02-09 08:00am
by Lucifer
I have both Netscape and Firefox on OSX, and they're remarkably similar. However, I don't know if Netscape has the same IDN problems as Firefox.

Posted: 2005-02-09 12:54pm
by Crayz9000
Lucifer wrote:I have both Netscape and Firefox on OSX, and they're remarkably similar. However, I don't know if Netscape has the same IDN problems as Firefox.
It's a Mozilla-based browser, so probably yes.

about:config should work if it's Netscape 7, and won't work if it's Netscape 6. Besides, if it's NS6 you should upgrade it due to an older security bug.

Posted: 2005-02-10 07:40am
by LadyTevar
Wow... that was easy. Took me only 30 sec.

Thanks!

Posted: 2005-02-10 09:29am
by Nieztchean Uber-Amoeba
Woah. That took me, like 10 seconds to toggle IDN to false.

FIREFOX FUCKING RULES!!!

Posted: 2005-02-11 11:00pm
by CelesKnight
Are you sure that that solution works?

I set the setting to false, rebooted, cleared the caches, checked that the setting was still false, and the "fake" link still works.

Either:
A) I'm misunderstanding the problem and/or solution
or
B) There may be people here who think they're protected but aren't.

This site gives a "permanent" solution, but I haven't tried it yet.

Posted: 2005-02-12 01:38am
by Crayz9000
... that's quite bizarre. When I first tried it, it prevented the IDN spoofed domain from working. Now (he did modify the link however) it does work.

Following what the guy said in the link you posted, I can see why. It's irritating that changes in about:config don't hold over. Anyway, I have tested the fix that he proposed and I can confirm it does work. But for most people, using the AdBlock extension fix that he gave would probably be easier.

Posted: 2005-02-24 08:12am
by Crayz9000
I have another update to add.

If you use vanilla Mozilla, then you can get the MultiZilla extension. Get the latest stable nightly, which is 1.8.x.x. Multizilla now features a "secret" hashing feature for SSL sites that will warn you of a spoofed IDN domain (I tested it -- the regular link still worked as before, but the more dangerous SSL link was noticed by Multizilla...

So if you use vanilla Mozilla, I would use Multizilla until the next version of Mozilla is released sans IDN support.

Posted: 2005-02-24 02:01pm
by darthdavid
I don't know if it's cause I'm using the debian build of FF but it was set to false by default. :D

Posted: 2005-02-24 02:55pm
by Crayz9000
Test the spoof page again and see if it works. Remember that as above, the network.enableIDN solution doesn't seem to be working properly... I don't know if it's the case for the Debian build.