Forum Moderators: open

Message Too Old, No Replies

Spoofing Flaw Found in Non IE Browsers

         

SuzyUK

8:34 pm on Feb 9, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



support for ASCII coding being used for the International Domain Name (IDN) specification in order to allow domains to be typed with country-specific characters such as the Spanish "ñ" or German "ü" has revealed a spoofing flaw..

Source [betanews.com]

Because the flaw lies in the basic implementation of IDN, it's unclear how browser vendors will protect their users. Mozilla developers say they are working on a long-term solution to the issue, and in the meantime will instruct users on disabling IDN support.

Source: [news.netcraft.com]

The attack can be disabled in Firefox and Mozilla by setting 'network.enableIDN' to false in the browser's configuration (enter about:config in the address bar to access the configuration fucntions). There is no known workaround yet for Opera or Safari

encyclo

9:15 pm on Feb 9, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



It's a potentially nasty one, and one of the inherent dangers with IDNs. There is an earlier thread discussing the issues over here [webmasterworld.com].

SuzyUK

9:28 pm on Feb 9, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Ah thanks encyclo, I did wonder I hadn't read it here.. just looked in the wrong place :o

The info I was looking for is in that thread too ~ the bit about the Firefox workaround not being reliable I mean.

Suzy

dgrimm

1:23 am on Feb 15, 2005 (gmt 0)

10+ Year Member



Looks like the Mozilla organization has formulated their response to this issue:

[weblogs.mozillazine.org...]