Mozilla/Firefox security exploit: Disable IDN support

Discussion in 'Windows Desktop Systems' started by NetRyder, Feb 7, 2005.

  1. NetRyder

    NetRyder Tech Junkie Folding Team

    Messages:
    13,256
    Location:
    New York City
    From the front-page:
    http://www.osnn.net/comments.php?shownews=11780

     
  2. NetRyder

    NetRyder Tech Junkie Folding Team

    Messages:
    13,256
    Location:
    New York City
    Re: Mozilla/Firefox users: Disable IDN support

    Update: Several users are now reporting that the fix does not necessarily work:
    http://it.slashdot.org/comments.pl?sid=138568&cid=11596841

    I tried setting the network.enableIDN flag to false, then visited the proof of concept page and I got an error when I tried to visit the fake Paypal link. All good. Then I restarted Firefox, tried again and the spoof still works. :s

    Edit: Confirmed. It's a single session fix. As soon as you close and restart the browser, the fix no longer works. Hopefully the Mozilla/Firefox folks release an official patch soon.
     
  3. NetRyder

    NetRyder Tech Junkie Folding Team

    Messages:
    13,256
    Location:
    New York City
    Alright, here's a temporary fix that actually works:

    http://forums.mozillazine.org/viewtopic.php?t=215178
     
  4. melon

    melon MS-DOS 2.0 Political User

    Messages:
    854
    Location:
    Ásgarðr
    Works perfectly. BTW, I didn't delete the lines, I just commented them out with a #.

    Melon
     
  5. Admiral Michael

    Admiral Michael Michaelsoft Systems CEO Folding Team

    ok, so for the fix to work its suppose to say not found when clicking on a spoof link?

    I used http://www.shmoo.com/idn/ to test. And uncommented results in meeow and commented results in site not found.
     
  6. Geffy

    Geffy Moderator Folding Team

    Messages:
    7,805
    Location:
    United Kingdom
    thats annoying, I hope apple get on to this soon
     
  7. Xie

    Xie - geek - Subscribed User Folding Team

    Messages:
    5,275
    Location:
    NY, USA
    What does disabling IDN do to your connection? (I'm not tops w/ networking)
     
  8. lynchknot

    lynchknot Moderator

    Messages:
    800
    Must re-edit when new plugin/extension is installed
    I just make a shortcut to the file and open in notepad - use "replace" (or "find") function. I just replace "IDN" with "#" - it works.[​IMG]

    Or you can use Proximitron:

     
  9. SPeedY_B

    SPeedY_B I may actually be insane.

    Messages:
    15,800
    Location:
    Midlands, England
    Ooh-err. Not good.

    Seconded. :D
     
  10. funky dredd

    funky dredd Moderator

    Messages:
    2,346
    Location:
    Florida
    What is proximitron?
     
  11. SPeedY_B

    SPeedY_B I may actually be insane.

    Messages:
    15,800
    Location:
    Midlands, England
    ...apparently :p (link)

    p.s. Fix for Safari users: http://forum.osnn.net/showthread.php?t=55474
     
  12. funky dredd

    funky dredd Moderator

    Messages:
    2,346
    Location:
    Florida
    Ya I found that after I posted. Thank you anyways SPeedY_B :)
     
  13. NetRyder

    NetRyder Tech Junkie Folding Team

    Messages:
    13,256
    Location:
    New York City
    Great. So we have temporary fixes for Mozilla/Firefox and Safari. :)
    *Wonders what the Opera folks are going to do*
     
  14. lynchknot

    lynchknot Moderator

    Messages:
    800
    Thanks Serlio, looks interesting.

    **edit - wonderful. you can still visit site but are warned (Japanese sites - or sites that use IDN characters work - instead of disabling IDN altogether)

    [​IMG]
     
    tom9042 and NetRyder like this.
  15. NetRyder

    NetRyder Tech Junkie Folding Team

    Messages:
    13,256
    Location:
    New York City
    Awesome! That's a much better fix. Where did you find it, lynch?
     
  16. Evil Marge

    Evil Marge I Rule Political User

    Messages:
    6,574
    Thanks Lynch thats one I can understand :laugh:
     
  17. lynchknot

    lynchknot Moderator

    Messages:
    800
    Where find? I live in Firefox world since Oct. 2002 - creating themes - so my finger is always on it's pulse.
     
  18. lynchknot

    lynchknot Moderator

    Messages:
    800
  19. NetRyder

    NetRyder Tech Junkie Folding Team

    Messages:
    13,256
    Location:
    New York City
    The Mozilla Foundation has posted an official response pertaining to this issue.
    http://www.mozillazine.org/talkback.html?article=6073

    I can't say I'm too pleased with the announcement. The fix lynchknot posted earlier in the thread seems like a better alternative to disabling IDN support completely.
     
  20. dreamliner77

    dreamliner77 The Analog Kid

    Messages:
    4,702
    Location:
    Red Sox Nation
    adding the fix as we speak.