Browser Hack, Firefox users beware
Moderator: Thanas
Re: Browser Hack, Firefox users beware
There's a reasonable amount, they just tend not to get publicised as much.Plekhanov wrote: Who'd have thought it a hack that doesn't affect microsoft stuff.
- Darth Wong
- Sith Lord
- Posts: 70028
- Joined: 2002-07-03 12:25am
- Location: Toronto, Canada
- Contact:
Ironically, this is precisely because IE has been so badly neglected. Since it doesn't support some of the newer encoding standards, and this hack relies on abuse of one of those newer encoding standards, it doesn't work on IE. It's a bit like saying that a cell-phone hack doesn't work on a land-line.
"It's not evil for God to do it. Or for someone to do it at God's command."- Jonathan Boyd on baby-killing
"you guys are fascinated with the use of those "rules of logic" to the extent that you don't really want to discussus anything."- GC
"I do not believe Russian Roulette is a stupid act" - Embracer of Darkness
"Viagra commercials appear to save lives" - tharkûn on US health care.
http://www.stardestroyer.net/Mike/RantMode/Blurbs.html
"you guys are fascinated with the use of those "rules of logic" to the extent that you don't really want to discussus anything."- GC
"I do not believe Russian Roulette is a stupid act" - Embracer of Darkness
"Viagra commercials appear to save lives" - tharkûn on US health care.
http://www.stardestroyer.net/Mike/RantMode/Blurbs.html
- Crayz9000
- Sith Apprentice
- Posts: 7329
- Joined: 2002-07-03 06:39pm
- Location: Improbably superpositioned
- Contact:
The fix for Firefox and other Mozilla-based browsers is trivially easy.
Simply go to about:config, and look for network.enableIDN. Set its value to false.
That's it. No more spoofing via IDN.
Simply go to about:config, and look for network.enableIDN. Set its value to false.
That's it. No more spoofing via IDN.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
- Zac Naloen
- Sith Acolyte
- Posts: 5488
- Joined: 2003-07-24 04:32pm
- Location: United Kingdom
for us idiots... how do you do that.. exactly...?Crayz9000 wrote:The fix for Firefox and other Mozilla-based browsers is trivially easy.
Simply go to about:config, and look for network.enableIDN. Set its value to false.
That's it. No more spoofing via IDN.
Member of the Unremarkables
Just because you're god, it doesn't mean you can treat people that way : - My girlfriend
Evil Brit Conspiracy - Insignificant guy
- Drooling Iguana
- Sith Marauder
- Posts: 4975
- Joined: 2003-05-13 01:07am
- Location: Sector ZZ9 Plural Z Alpha
Exactly what he said. Type "about:config" in the URL bar, scroll down until you find network.enableIDN and set it to false.Zac Naloen wrote:for us idiots... how do you do that.. exactly...?Crayz9000 wrote:The fix for Firefox and other Mozilla-based browsers is trivially easy.
Simply go to about:config, and look for network.enableIDN. Set its value to false.
That's it. No more spoofing via IDN.
:D
"Stop! No one can survive these deadly rays!"
"These deadly rays will be your death!"
- Thor and Akton, Starcrash
"Before man reaches the moon your mail will be delivered within hours from New York to California, to England, to India or to Australia by guided missiles.... We stand on the threshold of rocket mail."
- Arthur Summerfield, US Postmaster General 1953 - 1961
"These deadly rays will be your death!"
- Thor and Akton, Starcrash
"Before man reaches the moon your mail will be delivered within hours from New York to California, to England, to India or to Australia by guided missiles.... We stand on the threshold of rocket mail."
- Arthur Summerfield, US Postmaster General 1953 - 1961
- Faram
- Bastard Operator from Hell
- Posts: 5271
- Joined: 2002-07-04 07:39am
- Location: Fighting Polarbears
Thanx for the tip Crayz9000
Zac Naloen here is a screenshot for you.
Zac Naloen here is a screenshot for you.
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]
"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus
Fear is the mother of all gods.
Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus
Fear is the mother of all gods.
Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
- Crayz9000
- Sith Apprentice
- Posts: 7329
- Joined: 2002-07-03 06:39pm
- Location: Improbably superpositioned
- Contact:
It's a Mozilla-based browser, so probably yes.Lucifer wrote:I have both Netscape and Firefox on OSX, and they're remarkably similar. However, I don't know if Netscape has the same IDN problems as Firefox.
about:config should work if it's Netscape 7, and won't work if it's Netscape 6. Besides, if it's NS6 you should upgrade it due to an older security bug.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
Wow... that was easy. Took me only 30 sec.
Thanks!
Thanks!
Nitram, slightly high on cough syrup: Do you know you're beautiful?
Me: Nope, that's why I have you around to tell me.
Nitram: You -are- beautiful. Anyone tries to tell you otherwise kill them.
"A life is like a garden. Perfect moments can be had, but not preserved, except in memory. LLAP" -- Leonard Nimoy, last Tweet
Me: Nope, that's why I have you around to tell me.
Nitram: You -are- beautiful. Anyone tries to tell you otherwise kill them.
"A life is like a garden. Perfect moments can be had, but not preserved, except in memory. LLAP" -- Leonard Nimoy, last Tweet
-
- Sith Devotee
- Posts: 3317
- Joined: 2004-10-15 08:57pm
- Location: Regina Nihilists' Guild Party Headquarters
- CelesKnight
- Padawan Learner
- Posts: 459
- Joined: 2003-08-20 11:45pm
- Location: USA
Are you sure that that solution works?
I set the setting to false, rebooted, cleared the caches, checked that the setting was still false, and the "fake" link still works.
Either:
A) I'm misunderstanding the problem and/or solution
or
B) There may be people here who think they're protected but aren't.
This site gives a "permanent" solution, but I haven't tried it yet.
I set the setting to false, rebooted, cleared the caches, checked that the setting was still false, and the "fake" link still works.
Either:
A) I'm misunderstanding the problem and/or solution
or
B) There may be people here who think they're protected but aren't.
This site gives a "permanent" solution, but I haven't tried it yet.
ASVS Class of 1997
BotM / HAB / KAC
BotM / HAB / KAC
- Crayz9000
- Sith Apprentice
- Posts: 7329
- Joined: 2002-07-03 06:39pm
- Location: Improbably superpositioned
- Contact:
... that's quite bizarre. When I first tried it, it prevented the IDN spoofed domain from working. Now (he did modify the link however) it does work.
Following what the guy said in the link you posted, I can see why. It's irritating that changes in about:config don't hold over. Anyway, I have tested the fix that he proposed and I can confirm it does work. But for most people, using the AdBlock extension fix that he gave would probably be easier.
Following what the guy said in the link you posted, I can see why. It's irritating that changes in about:config don't hold over. Anyway, I have tested the fix that he proposed and I can confirm it does work. But for most people, using the AdBlock extension fix that he gave would probably be easier.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
- Crayz9000
- Sith Apprentice
- Posts: 7329
- Joined: 2002-07-03 06:39pm
- Location: Improbably superpositioned
- Contact:
I have another update to add.
If you use vanilla Mozilla, then you can get the MultiZilla extension. Get the latest stable nightly, which is 1.8.x.x. Multizilla now features a "secret" hashing feature for SSL sites that will warn you of a spoofed IDN domain (I tested it -- the regular link still worked as before, but the more dangerous SSL link was noticed by Multizilla...
So if you use vanilla Mozilla, I would use Multizilla until the next version of Mozilla is released sans IDN support.
If you use vanilla Mozilla, then you can get the MultiZilla extension. Get the latest stable nightly, which is 1.8.x.x. Multizilla now features a "secret" hashing feature for SSL sites that will warn you of a spoofed IDN domain (I tested it -- the regular link still worked as before, but the more dangerous SSL link was noticed by Multizilla...
So if you use vanilla Mozilla, I would use Multizilla until the next version of Mozilla is released sans IDN support.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
-
- Pathetic Attention Whore
- Posts: 5470
- Joined: 2003-02-17 12:04pm
- Location: Bat Country!
- Crayz9000
- Sith Apprentice
- Posts: 7329
- Joined: 2002-07-03 06:39pm
- Location: Improbably superpositioned
- Contact:
Test the spoof page again and see if it works. Remember that as above, the network.enableIDN solution doesn't seem to be working properly... I don't know if it's the case for the Debian build.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF