troubleshooting/tutorials/security

02/07/2005, 11:35am, EST

Monday, February 7th

Security hole threatens Safari, Firefox, others

A security hole in Firefox and Safari could enable malicious Web sites to mislead users. The exploit involves International Domain Name (IDN) handling. A proof of concept is available to demonstrate the exploit. There is currently no known workaround for Safari, and a potential fix Mozilla is questioned. Internet Explorer is not affected. Camino, however, appears to be vulnerable to the exploit.


Filed under: troubleshooting

, , 18comments, del.icio.us, slashdot, digg, buzz


18 comments
Reader Reactions (Please use <i></i> for italic text)

subscribe to comments
for this article




Expand All   Global Settings
iCab is "safe" too.
0
02/07, 12:14pm, EST
iCab seems to be immune too. I get "Not Found" errors.
Fresh-Faced Recruit
Joined Dec 2003
User is offline
That's it...
0
02/07, 1:25pm, EST
...I'm moving over to Windows.
Mac Elite
Joined Oct 2001
User is offline
Not a big deal...
0
02/07, 1:34pm, EST
We can just view the source code of every page we visit and examine each link...err..um...nevermind.
Fresh-Faced Recruit
Joined Aug 2001
User is offline
Workaround for Mozilla...
0
02/07, 1:35pm, EST
Workaround for Mozilla-based products (Mozilla, Firefox, etc.):

Enter about:config in the address bar and click Go or hit Enter.
Scroll down to the network.enableIDN preference and double-click so the value is says "false".

The problem is that the setting will be ignored the next time Firefox is started and will have to be reset each time the browser is launched (even if the pref says "false").
Grizzled Veteran
Joined Apr 2001
User is offline
Not a security hole
0
02/07, 1:40pm, EST
As dumb as it may sound, this is NOT a true "security hole".

This is a pure abuse and disregard of the rules set for IDN handling, where top-level registrars are supposed to be as restrictive as possible in handing out IDN coded domain names. Of course, the ICANN turns a blind eye on the .com, .net and .org TLDs, opening up a can of worms in regard to phishing. Other TLDs are supposed to stick with their alphabet only to minimise problems, but some TLDs have not honoured this ( like Poland f.ex. - they would happily register "ibm·com.pl" - see a possible conflict with "ibm.com.pl" ? :)
Junior Member
Joined Sep 2004
User is offline
workaround
0
02/07, 1:43pm, EST
That Firefox workaround is potentially disastrous, because it makes you THINK you've fixed it and you haven't! (I just confirmed that the setting is lost when you restart, even if it's still set to "false." That's a plain old BUG in Firefox.)
Fresh-Faced Recruit
Joined Dec 1999
User is offline
Agreed...
0
02/07, 1:50pm, EST
adamschneider: Agreed. Firefox forgets to read the preference at startup or something but shows its saved value in the about:config information. I'll have to re-double-click it each time I start up. Yes...it does suck.
Grizzled Veteran
Joined Apr 2001
User is offline
manually...
0
02/07, 1:51pm, EST
i believe you can edit the file manually. everything edited with the "about:config" thing is not permanent. i cant remember where it is though right off hand. not at my mac at the moment. at work on a peecee.
Grizzled Veteran
Joined May 2002
User is offline
Etiquette?
0
02/07, 2:01pm, EST
Check the details at:

http://www.shmoo.com/idn/homograph.txt

Notice the timeline at the end of the document. They reported the problem to the vendors January 19, 2005, and published details of the exploit yesterday (February 6). Does security etiquette call for more time than that? I thought at least 60 days was the norm.
Fresh-Faced Recruit
Joined Sep 2000
User is offline
prefs.js
0
02/07, 2:01pm, EST
It's stored in the prefs.js file of your profile and it looks like it's stored correctly when altered by the about:config panel. It looks like the setting is not read at startup though.
Grizzled Veteran
Joined Apr 2001
User is offline
additional comments:..1..2..Next
Your Comments

In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


Registered Member?
macnn forums login:

macnn forums password:

Not a member of the MacNN forums? Register now for free.

RSS Feeds

Have the latest content delivered to your desktop via RSS. Use the links below to get access to a specific blog, news, or reviews feed.



  MacNN -all

  MacNN Reviews

  MacNN Podcasts

  iPodNN

  Electronista

  Left Lane News
Turn your laptop into CASH: Sell us your used laptop. Working or not. Get money FAST. Instant online quote. Shipping is FREE.

Check Out the VIERA from Panasonic!: Enter a New Visual Era with Panasonic VIERA HDTVs. An Enhanced Experience.

Apple: Browse a huge selection now. Find exactly what you want today.

Food & Dining Directory: Find Local Food & Dining Near You. Get Address & Phone Numbers.

The New iPhone: The New York Times takes a look at Apple's latest release." b Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.