FireFox Exploit (And others, but not IE this time)

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • goBigtime
    Confirmed User
    • Nov 2002
    • 7761

    #1

    FireFox Exploit (And others, but not IE this time)

    Test it here...

    http://www.shmoo.com/idn/

    There is a link to the advisory there too.


    In firefox you can fix it yourself until they issue a new version:

    Type about:config in your address bar.

    Scroll down to network.enableIDN and double-click it to set it to false

    IDN = International Domain Name
  • goBigtime
    Confirmed User
    • Nov 2002
    • 7761

    #2
    Vulnerable browsers include (but are not limited to):

    Most mozilla-based browsers (Firefox 1.0, Camino .8.5, Mozilla 1.6, etc)
    Safari 1.2.5
    Opera 7.54
    Omniweb 5


    Vendor Responses:

    Verisign: No response yet.
    Apple: No response yet.
    Opera: They believe they have correctly implemented IDN, and will not be
    making any changes.
    Mozilla: Working on finding a good long-term solution; provided clear
    workaround for disabling IDN.



    Mozilla/Firefox first to offer a fix

    Comment

    • Jace
      FBOP Class Of 2013
      • Jan 2004
      • 35562

      #3
      rofl, i thought firefox was immune to this shit?

      Comment

      • quantum-x
        Confirmed User
        • Feb 2002
        • 6863

        #4
        Slashdot cross poster eh?

        It's not actually so much that IE isn't vulnerable, it just doesnt support the IDN standard. If you installed the plugin, it will be.

        On the flip side, it's not so much FF that is vulnerable as the plugin
        PrettyInCash.com - BoozedGFs.com - TeenGFs.com - JizzGFs.com- MilfUploads.com -

        Comment

        • e-god
          Confirmed User
          • Jan 2003
          • 1738

          #5
          as firefox is getting more popular more exploits are being found, waiting till nerds will start to write malicious viruses and worms that will go thru firefox

          Comment

          • goBigtime
            Confirmed User
            • Nov 2002
            • 7761

            #6
            Originally posted by quantum-x
            Slashdot cross poster eh?

            I don't read the forums much, usually just the headlines.

            A friend IM'd me with the info a few mins before I started this thread.

            Comment

            • goBigtime
              Confirmed User
              • Nov 2002
              • 7761

              #7
              Originally posted by e-god
              as firefox is getting more popular more exploits are being found, waiting till nerds will start to write malicious viruses and worms that will go thru firefox
              With firefox, If they don't write and exploit them within an hour of the exploit being released then they'll probably be too late :P

              Comment

              Working...