Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Exploit for every browser except IE...

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Internet Discussion
Register FAQ Community Calendar

Exploit for every browser except IE...
Reply
 
Thread Tools
Old 07-02-2005, 20:19   #1
Richard M
Inactive
 
Join Date: Jun 2003
Location: Los Angeles, CA
Age: 46
Posts: 6,343
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Exploit for every browser except IE...

...and with good reason:
Quote:
East coast hacker con Shmoocon ended today and they had a nasty browser exploit to show off... using International Domain Name (IDN) character support to display fake domain names in links and the address bar. Their examples use Paypal (with SSL too) and this looks very useful for phishing attacks. Interesting note that it works in every browser *except* IE (which makes this exploit a lot less dangerous in the end, I suppose)."v The reason IE isn't vulnerable is because it doesn't natively support IDN; with the right plug-in, it too is vulnerable.
http://it.slashdot.org/article.pl?si...4&tid=95&tid=1

http://www.shmoo.com/idn/
Richard M is offline   Reply With Quote
Advertisement
Old 07-02-2005, 20:39   #2
MovedGoalPosts
Inactive
 
MovedGoalPosts's Avatar
 
Join Date: Jun 2003
Location: 127.0.0.1
Age: 61
Posts: 15,868
MovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny stars
MovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny stars
Re: Exploit for every browser except IE...

Mr Gates has actually provided software that by default is more secure than the offerings of others

M$ much vaunted security edicts must count for something then. Wohoo
MovedGoalPosts is offline   Reply With Quote
Old 07-02-2005, 20:41   #3
punky
Inactive
 
Join Date: Jun 2003
Age: 44
Posts: 14,750
punky has a golden aurapunky has a golden aura
punky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aura
Re: Exploit for every browser except IE...

It is ironic though, that being a naff, featureless browser is what stops the virus from attacking it.
punky is offline   Reply With Quote
Old 07-02-2005, 20:47   #4
homealone
Guest
 
Posts: n/a
Re: Exploit for every browser except IE...

thanks to mr_love_monkey for a potential workaround for Firefox

http://www.cableforum.co.uk/board/sh...65&postcount=1

  Reply With Quote
Old 07-02-2005, 21:10   #5
nffc
cf.mega poster
 
nffc's Avatar
 
Join Date: Jul 2004
Location: chavvy Nottingham
Age: 42
Services: Freeview, Sky+, 100 Mb/s VM BB, mega i7 PC, iPhone 13, Macbook Air
Posts: 7,453
nffc has a nice shiny star
nffc has a nice shiny starnffc has a nice shiny starnffc has a nice shiny starnffc has a nice shiny starnffc has a nice shiny starnffc has a nice shiny starnffc has a nice shiny starnffc has a nice shiny starnffc has a nice shiny starnffc has a nice shiny starnffc has a nice shiny starnffc has a nice shiny starnffc has a nice shiny starnffc has a nice shiny starnffc has a nice shiny starnffc has a nice shiny starnffc has a nice shiny star
Re: Exploit for every browser except IE...

It's pretty easy to fix though.
__________________


nffc is offline   Reply With Quote
Old 07-02-2005, 22:49   #6
Halcyon
Hello !
 
Halcyon's Avatar
 
Join Date: Mar 2004
Location: Somewhere
Services: Sky, AppleTV, Netflix
Posts: 16,787
Halcyon is seeing silvered starsHalcyon is seeing silvered starsHalcyon is seeing silvered starsHalcyon is seeing silvered stars
Halcyon is seeing silvered starsHalcyon is seeing silvered starsHalcyon is seeing silvered starsHalcyon is seeing silvered starsHalcyon is seeing silvered starsHalcyon is seeing silvered starsHalcyon is seeing silvered starsHalcyon is seeing silvered starsHalcyon is seeing silvered starsHalcyon is seeing silvered starsHalcyon is seeing silvered starsHalcyon is seeing silvered starsHalcyon is seeing silvered starsHalcyon is seeing silvered starsHalcyon is seeing silvered starsHalcyon is seeing silvered starsHalcyon is seeing silvered starsHalcyon is seeing silvered starsHalcyon is seeing silvered starsHalcyon is seeing silvered stars
Re: Exploit for every browser except IE...

Wow.
Microsoft can have a little "It didnt get our browser" celebration today.
for once that IE prooves to be useful.
__________________
.
-

Halcyon is offline   Reply With Quote
Old 08-02-2005, 02:33   #7
El Diablo
Inactive
 
Join Date: Jun 2003
Location: Oxford
Posts: 125
El Diablo is an unknown quantity at this point
Re: Exploit for every browser except IE...

Quote:
Originally Posted by Halcyon
Wow.
Microsoft can have a little "It didnt get our browser" celebration today.
for once that IE prooves to be useful.
Ummmm... I don't get this. Surely this issue has nothing to do with M$ IE being 'secure' but down to the fact that these people managed to register an IDN like that anyway? If anything, Verisign are at fault for failing to protect their existing customer's interest when opening up xn-- registrations, something that not *all* registries are doing... yet. There's a consultation paper going out shortly for registrations under .uk, to establish whether there's a requirement to handle IDNAs or not. I can imagine that there will be a need, but at least with .uk, we're safe in the assurance that we won't get shafted by the registry - unlike gTLDs whereby there's very little public consultation on the effects of opening up new protocols, such as IDNA. We've seen Verisign do daft things before, this isn't anything new and is not something that should be directed at browser vendors. If anything, M$ have once again displayed their inability to keep up with the times by not supporting IDNA anyhow, why are they the only ones that don't? And ... no, before you suggest it, it has nothing to do with security conscience

Quote:
Originally Posted by punky
It is ironic though, that being a naff, featureless browser is what stops the virus from attacking it.
Yeah, that's exactly the point. a) it wasn't a virus, there's quite a difference here; and b) IE *is* featureless, they just happened to be lucky here, in that it's *so* featureless it doesn't support IDNs - yet there *are* registries out there that do... Why are M$ so far behind?

Quote:
Originally Posted by MovedGoalPosts
Mr Gates has actually provided software that by default is more secure than the offerings of others

M$ much vaunted security edicts must count for something then. Wohoo
Nah, again... IE is *not* more secure - it just doesn't support the new IDN protocol, simple. That's *not* necessarily a good thing, whatsoever. The fact that IE is upgradable to support IDN is a distinct indication of this. If it was a security issue, then the upgrade wouldn't be available. It simply hasn't been fully distributed because there is not yet a widespread requirement for it - although IDN has been launched in various countries, with much success.

El Diablo is offline   Reply With Quote
Old 08-02-2005, 09:17   #8
Electrolyte01
Guest
 
Posts: n/a
Re: Exploit for every browser except IE...

I wonder if Avant is vulnerable, since it MAY have a plugin for it
  Reply With Quote
Old 08-02-2005, 10:04   #9
Mr_love_monkey
Inactive
 
Mr_love_monkey's Avatar
 
Join Date: Jun 2003
Location: London way
Age: 49
Services: Sarcasm
Posts: 8,376
Mr_love_monkey has a pair of shiny starsMr_love_monkey has a pair of shiny starsMr_love_monkey has a pair of shiny starsMr_love_monkey has a pair of shiny starsMr_love_monkey has a pair of shiny starsMr_love_monkey has a pair of shiny stars
Mr_love_monkey has a pair of shiny starsMr_love_monkey has a pair of shiny starsMr_love_monkey has a pair of shiny starsMr_love_monkey has a pair of shiny starsMr_love_monkey has a pair of shiny stars
Re: Exploit for every browser except IE...

Quote:
Originally Posted by homealone
thanks to mr_love_monkey for a potential workaround for Firefox

http://www.cableforum.co.uk/board/sh...65&postcount=1


I was just going to say I'd already mentioned that... still as long as as many people as possible read it, that's all that matters
Mr_love_monkey is offline   Reply With Quote
Old 09-02-2005, 00:10   #10
dragon
Inactive
 
Join Date: Jan 2004
Posts: 3,898
dragon has reached the bronze age
dragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze age
Re: Exploit for every browser except IE...

and an even more simple work around is not to click links to things like paypal and to type em in yourself...

but seriously its probably not as such a big thing as everybody makes out and as someone previously said its more to do with the registry itself rather than the browsers that support the feature...
dragon is offline   Reply With Quote
Old 09-02-2005, 01:02   #11
Raistlin
Inactive
 
Join Date: Feb 2004
Location: There's no place like 127.0.0.1
Services: Depends on the person and the price they're offering
Posts: 12,384
Raistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered stars
Raistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered stars
Re: Exploit for every browser except IE...

We'll probably find that the latest round of Windows Updates have enabled IDN support on IE
Raistlin is offline   Reply With Quote
Old 09-02-2005, 08:18   #12
dragon
Inactive
 
Join Date: Jan 2004
Posts: 3,898
dragon has reached the bronze age
dragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze age
Re: Exploit for every browser except IE...

Quote:
Originally Posted by Raistlin
We'll probably find that the latest round of Windows Updates have enabled IDN support on IE
lol, wouldn't put it past em
dragon is offline   Reply With Quote
Old 09-02-2005, 17:08   #13
MadGamer
Inactive
 
MadGamer's Avatar
 
Join Date: Jun 2003
Location: Essex
Age: 37
Services: Sky multiroom (Sky Q) Sky Fibre Unlimited Sky Landline
Posts: 8,851
MadGamer has a nice shiny star
MadGamer has a nice shiny starMadGamer has a nice shiny star
Re: Exploit for every browser except IE...

Quote:
Originally Posted by Raistlin
We'll probably find that the latest round of Windows Updates have enabled IDN support on IE
MadGamer is offline   Reply With Quote
Old 16-02-2005, 00:25   #14
Richard M
Inactive
 
Join Date: Jun 2003
Location: Los Angeles, CA
Age: 46
Posts: 6,343
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Re: Exploit for every browser except IE...

Update: Mozilla have now decided to disable IDN support by default in their browsers.
More info here:
http://slashdot.org/article.pl?sid=0...&tid=154&tid=1

EDIT: I've never seen one of these URLs before, but in case you're wondering what it looks like...
http://vÃÃâ€*’Ãâ...€šÃ‚¤vtak.se/ (doesn't work in IE)
Richard M is offline   Reply With Quote
Old 16-02-2005, 00:49   #15
punky
Inactive
 
Join Date: Jun 2003
Age: 44
Posts: 14,750
punky has a golden aurapunky has a golden aura
punky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aura
Re: Exploit for every browser except IE...

Hmmm. I have disabled IDN in FireFox, but that website works. I thought it would have given me some warning or error.
punky is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 13:06.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum