IDN spoofing in Firefox

Written by

in

firefox burning?Sadly there seems to be quite a critical bug in the current version of Firefox which allow hackers/scammers to spoof the URL displayed in the address bar and the SSL certificate.

The vulnerability impacts every browser that uses the open-source Gecko browser kernel, almost all except IE, because of a flaw in handling International Domain Names (IDN).

This is very unfortunate for the Mozilla Foundation which recently released Firefox 1.0 alongside with all the browser which uses the Gecko kernel.

The bug was reported Monday 10th of February 2005 and currently none of the vendors have provided fixes for the flaw.

http://secunia.com/multiple_browsers_idn_spoofing_test/

Comments

3 responses to “IDN spoofing in Firefox”

  1. Patrick Weber Avatar

    Sheesh. That’s really bad. Sounds like phishing is up again. Well all anyone needs to remember is to copy the url by highlighting it and copying, dont click. If it isnt a scam then the copied link should work.

    On another note. I checked my audioscrobbler account and i noticed this:

    http://img157.exs.cx/img157/3329/audioscrobbler7ok.jpg

    Looks like i like someones music :P.

  2. tommie Avatar

    Patrick Weber: hehe, how cool. Thanks for listening to my music! … 🙂

Leave a Reply

Your email address will not be published. Required fields are marked *