Exploit for every browser except IE...
07-02-2005, 20:19
|
#1
|
|
Inactive
Join Date: Jun 2003
Location: Los Angeles, CA
Age: 46
Posts: 6,343
|
Exploit for every browser except IE...
...and with good reason:
Quote:
|
East coast hacker con Shmoocon ended today and they had a nasty browser exploit to show off... using International Domain Name (IDN) character support to display fake domain names in links and the address bar. Their examples use Paypal (with SSL too) and this looks very useful for phishing attacks. Interesting note that it works in every browser *except* IE (which makes this exploit a lot less dangerous in the end, I suppose)."v The reason IE isn't vulnerable is because it doesn't natively support IDN; with the right plug-in, it too is vulnerable.
|
http://it.slashdot.org/article.pl?si...4&tid=95&tid=1
http://www.shmoo.com/idn/
|
|
|
07-02-2005, 20:39
|
#2
|
|
Inactive
Join Date: Jun 2003
Location: 127.0.0.1
Age: 61
Posts: 15,868
|
Re: Exploit for every browser except IE...
Mr Gates has actually provided software that by default is more secure than the offerings of others
M$ much vaunted security edicts must count for something then. Wohoo
|
|
|
07-02-2005, 20:41
|
#3
|
|
Inactive
Join Date: Jun 2003
Age: 44
Posts: 14,750
|
Re: Exploit for every browser except IE...
It is ironic though, that being a naff, featureless browser is what stops the virus from attacking it.
|
|
|
07-02-2005, 21:10
|
#5
|
|
cf.mega poster
Join Date: Jul 2004
Location: chavvy Nottingham
Age: 42
Services: Freeview, Sky+, 100 Mb/s VM BB, mega i7 PC, iPhone 13, Macbook Air
Posts: 7,453
|
Re: Exploit for every browser except IE...
It's pretty easy to fix though.
|
|
|
07-02-2005, 22:49
|
#6
|
|
Hello !
Join Date: Mar 2004
Location: Somewhere
Services: Sky, AppleTV, Netflix
Posts: 16,787
|
Re: Exploit for every browser except IE...
Wow.
Microsoft can have a little "It didnt get our browser" celebration today.
for once that IE prooves to be useful.
|
|
|
08-02-2005, 02:33
|
#7
|
|
Inactive
Join Date: Jun 2003
Location: Oxford
Posts: 125
|
Re: Exploit for every browser except IE...
Quote:
|
Originally Posted by Halcyon
Wow.
Microsoft can have a little "It didnt get our browser" celebration today.
for once that IE prooves to be useful. 
|
Ummmm... I don't get this. Surely this issue has nothing to do with M$ IE being 'secure' but down to the fact that these people managed to register an IDN like that anyway? If anything, Verisign are at fault for failing to protect their existing customer's interest when opening up xn-- registrations, something that not *all* registries are doing... yet. There's a consultation paper going out shortly for registrations under .uk, to establish whether there's a requirement to handle IDNAs or not. I can imagine that there will be a need, but at least with .uk, we're safe in the assurance that we won't get shafted by the registry - unlike gTLDs whereby there's very little public consultation on the effects of opening up new protocols, such as IDNA. We've seen Verisign do daft things before, this isn't anything new and is not something that should be directed at browser vendors. If anything, M$ have once again displayed their inability to keep up with the times by not supporting IDNA anyhow, why are they the only ones that don't? And ... no, before you suggest it, it has nothing to do with security conscience
Quote:
|
Originally Posted by punky
It is ironic though, that being a naff, featureless browser is what stops the virus from attacking it.
|
Yeah, that's exactly the point. a) it wasn't a virus, there's quite a difference here; and b) IE *is* featureless, they just happened to be lucky here, in that it's *so* featureless it doesn't support IDNs - yet there *are* registries out there that do... Why are M$ so far behind?
Quote:
|
Originally Posted by MovedGoalPosts
Mr Gates has actually provided software that by default is more secure than the offerings of others
M$ much vaunted security edicts must count for something then. Wohoo
|
Nah, again... IE is *not* more secure - it just doesn't support the new IDN protocol, simple. That's *not* necessarily a good thing, whatsoever. The fact that IE is upgradable to support IDN is a distinct indication of this. If it was a security issue, then the upgrade wouldn't be available. It simply hasn't been fully distributed because there is not yet a widespread requirement for it - although IDN has been launched in various countries, with much success.
|
|
|
08-02-2005, 09:17
|
#8
|
|
Guest
|
Re: Exploit for every browser except IE...
I wonder if Avant is vulnerable, since it MAY have a plugin for it
|
|
|
|
08-02-2005, 10:04
|
#9
|
|
Inactive
Join Date: Jun 2003
Location: London way
Age: 49
Services: Sarcasm
Posts: 8,376
|
Re: Exploit for every browser except IE...
Quote:
|
Originally Posted by homealone
|
I was just going to say I'd already mentioned that... still as long as as many people as possible read it, that's all that matters
|
|
|
09-02-2005, 00:10
|
#10
|
|
Inactive
Join Date: Jan 2004
Posts: 3,898
|
Re: Exploit for every browser except IE...
and an even more simple work around is not to click links to things like paypal and to type em in yourself...
but seriously its probably not as such a big thing as everybody makes out and as someone previously said its more to do with the registry itself rather than the browsers that support the feature...
|
|
|
09-02-2005, 01:02
|
#11
|
|
Inactive
Join Date: Feb 2004
Location: There's no place like 127.0.0.1
Services: Depends on the person and the price they're offering
Posts: 12,384
|
Re: Exploit for every browser except IE...
We'll probably find that the latest round of Windows Updates have enabled IDN support on IE
|
|
|
09-02-2005, 08:18
|
#12
|
|
Inactive
Join Date: Jan 2004
Posts: 3,898
|
Re: Exploit for every browser except IE...
Quote:
|
Originally Posted by Raistlin
We'll probably find that the latest round of Windows Updates have enabled IDN support on IE 
|
lol, wouldn't put it past em
|
|
|
09-02-2005, 17:08
|
#13
|
|
Inactive
Join Date: Jun 2003
Location: Essex
Age: 37
Services: Sky multiroom (Sky Q)
Sky Fibre Unlimited
Sky Landline
Posts: 8,851
|
Re: Exploit for every browser except IE...
Quote:
|
Originally Posted by Raistlin
We'll probably find that the latest round of Windows Updates have enabled IDN support on IE 
|
|
|
|
16-02-2005, 00:49
|
#15
|
|
Inactive
Join Date: Jun 2003
Age: 44
Posts: 14,750
|
Re: Exploit for every browser except IE...
Hmmm. I have disabled IDN in FireFox, but that website works. I thought it would have given me some warning or error.
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +1. The time now is 14:47.
|