PDA

View Full Version : New nasty browser URL spoofing exploit


AncientPC
02-08-2005, 03:15 PM
This affects all web browsers that support IDN functionallity. That's basically all browers OTHER THAN IE. (Microsoft actually dodged a bullet this time by making their browser NOT compliant with web standards. /images/graemlins/smirk.gif )

Explanation:
http://www.shmoo.com/idn/homograph.txt

Examples:
http://www.shmoo.com/idn/

Phat Mack
02-08-2005, 04:02 PM
Interesting...

lucas9000
02-08-2005, 04:26 PM
the mozilla/firefox fix could not be easier.

if you don't want to read the article...

type "about:config" in your address bar and press enter (leave out the quotes)

scroll down to network.enableIDN

change it to false (just double-click it i think)

done.