Reply
Old February 7th, 2005 Top | #1

OSNN Subscriber
OSNN Folding Team  
NetRyder's Avatar
Tech Junkie
Joined: April 2002
Location: New York City
Posts: 13,575
Reputation: 4260
Power: 274

Default Mozilla/Firefox security exploit: Disable IDN support

From the front-page:
http://www.osnn.net/comments.php?shownews=11780

You can disable IDN support in Mozilla products by setting 'network.enableIDN' to false. There is no known workaround for Opera or Safari. Vendor responses have been varied with VeriSign and Apple failing to respond but Opera believing they have correctly implemented IDN, and will not be making any changes (oops). Mozilla are currently working on finding a good long-term solution. The company provided a clear workaround for disabling IDN temporarily until it can better address the issue.
NetRyder is offline   Reply With Quote
Old February 7th, 2005 Top | #2

OSNN Subscriber
OSNN Folding Team  
NetRyder's Avatar
Tech Junkie
Joined: April 2002
Location: New York City
Posts: 13,575
Reputation: 4260
Power: 274

Default Re: Mozilla/Firefox users: Disable IDN support

Update: Several users are now reporting that the fix does not necessarily work:
http://it.slashdot.org/comments.pl?s...8&cid=11596841

I tried setting the network.enableIDN flag to false, then visited the proof of concept page and I got an error when I tried to visit the fake Paypal link. All good. Then I restarted Firefox, tried again and the spoof still works.

Edit: Confirmed. It's a single session fix. As soon as you close and restart the browser, the fix no longer works. Hopefully the Mozilla/Firefox folks release an official patch soon.
NetRyder is offline   Reply With Quote
Old February 8th, 2005 Top | #3

OSNN Subscriber
OSNN Folding Team  
NetRyder's Avatar
Tech Junkie
Joined: April 2002
Location: New York City
Posts: 13,575
Reputation: 4260
Power: 274

Default Re: Mozilla/Firefox security exploit: Disable IDN support

Alright, here's a temporary fix that actually works:

The workaround for firefox seems to be an edit to your compreg.dat.

For windows
c:\Documents and Settings\$USER\Application Data\Mozilla\Firefox\Profiles\default.random\compreg.dat

For UNIX
~/.mozilla/firefox/default.random/compreg.dat

Removing the line that references IDN makes the problem go away. Using Find, there was a single reference for the UNIX host and 2 for the Win32 host. Removing the lines and restarting the browser makes the attack fail regardless of the about:config/userprefs.js value.

Here's an example entry.

{4byteshex-2byteshex-2byteshex-2byteshex-6byteshex},@mozilla.org/network/idn-service;1,,nsIDNService,rel:libnecko.so

Instead of deleting the line (1 in Linux) or lines (2 in Win) you can just comment them out by using the character #
http://forums.mozillazine.org/viewtopic.php?t=215178
NetRyder is offline   Reply With Quote
Old February 8th, 2005 Top | #4
 
melon's Avatar
MS-DOS 2.0
Joined: February 2002
Location: Ásgarđr
Posts: 981
Reputation: 420
Power: 112

Default Re: Mozilla/Firefox security exploit: Disable IDN support

Works perfectly. BTW, I didn't delete the lines, I just commented them out with a #.

Melon
melon is offline   Reply With Quote
Old February 8th, 2005 Top | #5

OSNN Subscriber
OSNN Folding Team  
Admiral Michael's Avatar
Michaelsoft Systems CEO
Joined: February 2003
Location: Hamilton, Ontario Canada Earth
Posts: 3,100
Blog Entries: 8
Reputation: 2000
Power: 138

Default Re: Mozilla/Firefox security exploit: Disable IDN support

ok, so for the fix to work its suppose to say not found when clicking on a spoof link?

I used http://www.shmoo.com/idn/ to test. And uncommented results in meeow and commented results in site not found.

Diego (Dell Inspiron 6400) - Intel Core 2 Duo T7200 | Mushkin 2GB (2x1024) DDR2 667MHz Memory | Western Digital 320GB 7200RPM SATA Hard Drive Black Edition| Intel Pro 3945 Wireless/Dell Wireless 355 Bluetooth | 15.4 inch UltraSharp WXGA+ Display @ 1440x900 on ATI Mobility Radeon X1400 | Microsoft Windows XP Professional SP3

My Site | My DVD Collection | My Network | Your Chevrolet Guy
Admiral Michael is offline   Reply With Quote
Old February 8th, 2005 Top | #6

OSNN Subscriber
OSNN Folding Team  
Geffy's Avatar
OSNN Veteran Addict
Joined: March 2002
Location: United Kingdom
Posts: 7,854
Reputation: 1490
Power: 190

Default Re: Mozilla/Firefox security exploit: Disable IDN support

thats annoying, I hope apple get on to this soon


blogtumbloglastfmflickr#rubyonrails@twitter
"I could be replaced with a very small shell script"
Geffy is offline   Reply With Quote
Old February 8th, 2005 Top | #7
Xie

OSNN Subscriber
OSNN Folding Team  
Xie's Avatar
- geek -
Joined: September 2003
Location: NY, USA
Posts: 5,426
Reputation: 1119
Power: 144

Default Re: Mozilla/Firefox security exploit: Disable IDN support

What does disabling IDN do to your connection? (I'm not tops w/ networking)

tehgeek | geeking out to tech | Chrome | IRC | *Parted Magic* | A+ Certified Professional
Xie is offline   Reply With Quote
Old February 8th, 2005 Top | #8
 
lynchknot's Avatar
OSNN Senior Addict
Joined: September 2002
Posts: 802
Reputation: 160
Power: 101

Default Re: Mozilla/Firefox security exploit: Disable IDN support

Must re-edit when new plugin/extension is installed
Isn't compreg.dat re-created anytime you install a new plugin/extension installed ? and wouldn't that overwrite the old file with the commented out line (not sure if FF respects the readonly attribute either, a la cookies.txt)... I haven't tested this as I haven't had the time and as i'm not really all that concerned with the IDN issue (based on my browsing habits)...
well i got a chance to test... and unless u make the file readonly the edit will be OVERwritten on new plugin/extension installation. also keeping readonly may prevent your newly installed extension/plugin from registering properly... SO... make sure reedit the file after extension/plugin installation....
I just make a shortcut to the file and open in notepad - use "replace" (or "find") function. I just replace "IDN" with "#" - it works.

Or you can use Proximitron:

Just added info ... Kye-U's Filters V4.30 for Proxomitron also prevent this exploit.

Kye-U's Forum (link to post) - http://www.kye-u.com/proxo/forums/i...=225&#entry3846
Direct Download of Kye-U's V4.30 .cfg ~Zipped~ - http://www.kye-u.com/proxo/dp/download.php?file=18
(I hope, you don't mind me posting a direct link Kye-U)
lynchknot is offline   Reply With Quote
Old February 8th, 2005 Top | #9

OSNN Subscriber  
SPeedY_B's Avatar
I may actually be insane.
Joined: March 2002
Location: Midlands, England
Posts: 16,127
Reputation: 2877
Power: 287

Default Re: Mozilla/Firefox security exploit: Disable IDN support

Ooh-err. Not good.

Originally Posted by Geffy
thats annoying, I hope apple get on to this soon
Seconded.
SPeedY_B is offline   Reply With Quote
Old February 8th, 2005 Top | #10
 
funky dredd's Avatar
OSNN Veteran Addict
Joined: August 2002
Location: Florida
Posts: 2,359
Reputation: 300
Power: 119

Default Re: Mozilla/Firefox security exploit: Disable IDN support

Originally Posted by lynchknot
Must re-edit when new plugin/extension is installed

I just make a shortcut to the file and open innotepad - use "replace" (or "find") function. I just replace "IDN" with"#" - it works.

Or you can use Proximitron:
What is proximitron?



funky dredd is offline   Reply With Quote
Old February 8th, 2005 Top | #11

OSNN Subscriber  
SPeedY_B's Avatar
I may actually be insane.
Joined: March 2002
Location: Midlands, England
Posts: 16,127
Reputation: 2877
Power: 287

Default Re: Mozilla/Firefox security exploit: Disable IDN support

Originally Posted by funky dredd
What is proximitron?
For those who have not yet been introduced, meet the Proxomitron: a free, highly flexible, user-configurable, small but very powerful, local HTTP web-filtering proxy.ű To become better acquainted, please see our online copy of the Proxomitron Help Files for a more comprehensive overview.

The current (and last) version of Proxomitron is Naoko 4.5, of which there were two releases, one in May of 2003 followed by one in June.ű Although very similar, there are distinct differences between the two which are not mentioned in either program's documentation.ű Both releases are available in the Files section.ű P.I's focus will be on the latest version -- the June release.
...apparently (link)

p.s. Fix for Safari users: http://forum.osnn.net/showthread.php?t=55474
SPeedY_B is offline   Reply With Quote
Old February 8th, 2005 Top | #12
 
funky dredd's Avatar
OSNN Veteran Addict
Joined: August 2002
Location: Florida
Posts: 2,359
Reputation: 300
Power: 119

Default Re: Mozilla/Firefox security exploit: Disable IDN support

Ya I found that after I posted. Thank you anyways SPeedY_B



funky dredd is offline   Reply With Quote
Old February 8th, 2005 Top | #13

OSNN Subscriber
OSNN Folding Team  
NetRyder's Avatar
Tech Junkie
Joined: April 2002
Location: New York City
Posts: 13,575
Reputation: 4260
Power: 274

Default Re: Mozilla/Firefox security exploit: Disable IDN support

Great. So we have temporary fixes for Mozilla/Firefox and Safari.
*Wonders what the Opera folks are going to do*
NetRyder is offline   Reply With Quote
Old February 9th, 2005 Top | #14
 
lynchknot's Avatar
OSNN Senior Addict
Joined: September 2002
Posts: 802
Reputation: 160
Power: 101

Default Re: Mozilla/Firefox security exploit: Disable IDN support

Originally Posted by Serlio
Another temporal workaround:

1. Install the extension Greasemonkey

2. Don't forget to restart Firefox to complete the extension installation.

3. Right click this link (DON'T FOLLOW THE LINK): IDN patch script and click "Install User Script..."

4. A window will appear. Press OK.

Finished. It will raise an alert when the URL contains IDN characters.

English language is not my best, so translation errors advices will be welcome
Thanks Serlio, looks interesting.

**edit - wonderful. you can still visit site but are warned (Japanese sites - or sites that use IDN characters work - instead of disabling IDN altogether)

lynchknot is offline   Reply With Quote
Old February 9th, 2005 Top | #15

OSNN Subscriber
OSNN Folding Team  
NetRyder's Avatar
Tech Junkie
Joined: April 2002
Location: New York City
Posts: 13,575
Reputation: 4260
Power: 274

Default Re: Mozilla/Firefox security exploit: Disable IDN support

Awesome! That's a much better fix. Where did you find it, lynch?
NetRyder is offline   Reply With Quote
Old February 9th, 2005 Top | #16
 
Evil Marge's Avatar
Angelic to the extreme
Joined: July 2002
Location: Teesside, the land of smog
Posts: 6,490
Reputation: 2193
Power: 179

Default Re: Mozilla/Firefox security exploit: Disable IDN support

Thanks Lynch thats one I can understand


Evil Marge is offline   Reply With Quote
Old February 9th, 2005 Top | #17
 
lynchknot's Avatar
OSNN Senior Addict
Joined: September 2002
Posts: 802
Reputation: 160
Power: 101

Default Re: Mozilla/Firefox security exploit: Disable IDN support

Where find? I live in Firefox world since Oct. 2002 - creating themes - so my finger is always on it's pulse.
lynchknot is offline   Reply With Quote
Old February 9th, 2005 Top | #18
 
lynchknot's Avatar
OSNN Senior Addict
Joined: September 2002
Posts: 802
Reputation: 160
Power: 101

Default Re: Mozilla/Firefox security exploit: Disable IDN support

Although I do not like to have another toolbar added to my browser some may want the updated spoofstick: http://www.jarnot.com/mt/archives/20...ox_spoof_s.php

lynchknot is offline   Reply With Quote
Old February 15th, 2005 Top | #19

OSNN Subscriber
OSNN Folding Team  
NetRyder's Avatar
Tech Junkie
Joined: April 2002
Location: New York City
Posts: 13,575
Reputation: 4260
Power: 274

Default Re: Mozilla/Firefox security exploit: Disable IDN support

The Mozilla Foundation has posted an official response pertaining to this issue.
http://www.mozillazine.org/talkback.html?article=6073

I can't say I'm too pleased with the announcement. The fix lynchknot posted earlier in the thread seems like a better alternative to disabling IDN support completely.
NetRyder is offline   Reply With Quote
Old February 18th, 2005 Top | #20
 
dreamliner77's Avatar
The Analog Kid
Joined: March 2002
Location: Red Sox Nation
Posts: 4,447
Reputation: 1004
Power: 152

Default Re: Mozilla/Firefox security exploit: Disable IDN support

adding the fix as we speak.

"You can fight without ever winning, but never win without a fight." -Neil Peart of RUSH
You could be walking down the street with an assualt rifle and an iPod and get arrested for having the iPod...

Nevtek :::: Holesaw::::Rockscene:::: Rockavision
dreamliner77 is offline   Reply With Quote

Reply

Bookmarks

Thread Tools

Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
building Mozilla and Firefox Complete Web Design & Coding 7 August 27th, 2005 2:37am
Mozilla Firefox 1.0.5 released NetRyder Windows Desktop Systems 7 July 13th, 2005 5:14am
mozilla (firefox) ? mooo Green Room 12 April 5th, 2005 9:57pm
Mozilla Firefox Icon (PNG) NetRyder Desktop Customisation 20 February 10th, 2004 9:33am
Tip: Disable New Windows (Mozilla) SPeedY_B Windows Desktop Systems 6 February 9th, 2003 9:47pm