This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

All Browsers But Ie At Risk To New Spoofing Scheme

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.techweb.com/article/printableAr…_section=700028
February 07, 2005
"A newly uncovered vulnerability in most browsers can allow hackers to spoof the URL displayed in the address bar and the SSL certificate, a security firm warned Monday. The one exception? Microsoft's Internet Explorer. Danish security company Secunia posted an alert describing the vulnerability – which affects Mozilla, Firefox, Safari, Opera, and Konqueror – as a "moderately critical" problem. The vulnerability impacts every browser built atop the open-source Geko browser kernel – nearly all except IE – because of a flaw in handling International Domain Names (IDN). Hackers can register domain names with certain international characters that resemble other commonly-used characters, said Secunia, to spoof the address and trick the user into thinking they're at a legitimate site and/or it's secured by SSL. Such spoofing vulnerabilities are typically exploited by phishers who try to dupe users into divulging financial information at bogus Web sites that resemble real-life banking, credit card, or retail sites.

The vulnerability has been confirmed in the latest version of Firefox, v. 1.0, as well as in Mozilla 1.7.5, Opera 7.54u1, Opera 7.54u2, Safari 1.2.4, Konqueror 3.2.2, and Netscape 7.2. Other editions of these browsers, however, may also be at risk, said Secunia, which posted an online test on its Web site: http://secunia.com/multiple_browsers_idn_spoofing_test/

Currently, none of the vendors have provided fixes for the flaw…"

:ph34r:
FYI…

Opera Calls for Consortium on IDN Fix
- http://www.betanews.com/article/Opera_Call…_Fix/1108759839
February 18, 2005
"Opera Software has called on its fellow browser makers and the Internet community as a whole to band together in an effort to fix the security issues related to Internationalized Domain Names. The IDN standard was called into question earlier this month following news that it could lead to domain spoofing and phishing attacks…"Technically speaking, Opera and other non-IE browsers run into a problem because they have implemented a standard correctly," Carsten Fischer, Opera's VP of Desktop Products, told BetaNews. IE is immune to the issue because it has yet to natively support IDN; however, a VeriSign plug-in can provide the functionality.

Earlier this week, Mozilla developers announced the next release of Firefox would disable IDN as a temporary corrective measure until a long-term solution is found. Opera says it will provide its own fix in an upcoming preview release of Opera 8, while noting any "solution must find a balance in how information is presented to the user"…"
FYI…

Firefox v1.0.1 released
- http://www.informationweek.com/shared/prin…icleID=60403364
"…The update covers a handful of security vulnerabilities and approximately 40 other fixes related to browser performance based on user feedback to Mozilla. The security vulnerabilities range from "moderately critical" in nature to not critical…One security patch addresses the problem of international domain name spoofing.."

>>> http://www.mozilla.org/download.html

:blink:
FYI…

Opera Tackles Phishing: Second Beta of the Opera Browser Available
- http://www.opera.com/pressreleases/en/2005/02/25/
"February 25, 2005
Opera Software ASA today released the second Beta version of its next browser, which includes an answer to the recent security debate over Web site spoofing. In this Beta, the browser displays security information inside the address bar, located next to the padlock icon that indicates the level of security present on a site.
The small, yellow security bar appears on secure sites and displays the name of the organization that owns the certificate. By clicking on the bar the user has access to more information about the validity of the certificate. These anti-spoof measures help users make educated decisions about a site's validity and security…To address Internationalized Domain Names (IDN) concerns, Opera's second Beta only displays localized domain names from certain top level domains (TLD). Opera selects TLDs that have established strict policies on the domain names they allow to be registered…Beta 2 is available for download at http://www.opera.com/download/?ver=8.0b2
For a complete list of features, view the changelog at http://www.opera.com/windows/changelogs/800b2/
Users must be aware that a beta should be used for preview purposes only, as it is not a final product and does not contain all the features that are expected with the final release."

:huh:
FYI…(-more- Update Incentive):

- http://secunia.com/virus_information/16634…und.exploit.31/
"…Bloodhound.Exploit.31 - Severity: 1/5 - Reported: 2005-03-30 01:09 …"

- http://www.sarc.com/avcenter/venc/data/blo…exploit.31.html
Last Updated on: March 29, 2005
"Bloodhound.Exploit.31 is a heuristic detection for the Mozilla Products Malformed GIF Buffer Overflow as described in CAN-2005-0399…"

- http://www.cve.mitre.org/cgi-bin/cvename.c…e=CAN-2005-0399
"Description: Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code via a GIF image with a crafted Netscape extension 2 block and buffer size."

:oops: :ph34r: :blink: