Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 02-09-2005, 06:47 PM   #1
goBigtime
Confirmed User
 
Join Date: Nov 2002
Posts: 7,761
FireFox Exploit (And others, but not IE this time)

Test it here...

http://www.shmoo.com/idn/

There is a link to the advisory there too.


In firefox you can fix it yourself until they issue a new version:

Type about:config in your address bar.

Scroll down to network.enableIDN and double-click it to set it to false

IDN = International Domain Name
goBigtime is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-09-2005, 06:56 PM   #2
goBigtime
Confirmed User
 
Join Date: Nov 2002
Posts: 7,761
Vulnerable browsers include (but are not limited to):

Most mozilla-based browsers (Firefox 1.0, Camino .8.5, Mozilla 1.6, etc)
Safari 1.2.5
Opera 7.54
Omniweb 5


Vendor Responses:

Verisign: No response yet.
Apple: No response yet.
Opera: They believe they have correctly implemented IDN, and will not be
making any changes.
Mozilla: Working on finding a good long-term solution; provided clear
workaround for disabling IDN.



Mozilla/Firefox first to offer a fix
goBigtime is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-09-2005, 07:00 PM   #3
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
rofl, i thought firefox was immune to this shit?
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-09-2005, 07:02 PM   #4
quantum-x
Confirmed User
 
quantum-x's Avatar
 
Join Date: Feb 2002
Location: ICQ: 251425 Fr/Au/Ca
Posts: 6,863
Slashdot cross poster eh?

It's not actually so much that IE isn't vulnerable, it just doesnt support the IDN standard. If you installed the plugin, it will be.

On the flip side, it's not so much FF that is vulnerable as the plugin
quantum-x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-09-2005, 07:08 PM   #5
e-god
Confirmed User
 
e-god's Avatar
 
Join Date: Jan 2003
Location: BabeLand
Posts: 1,736
as firefox is getting more popular more exploits are being found, waiting till nerds will start to write malicious viruses and worms that will go thru firefox
__________________
e-god is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-09-2005, 07:09 PM   #6
goBigtime
Confirmed User
 
Join Date: Nov 2002
Posts: 7,761
Quote:
Originally Posted by quantum-x
Slashdot cross poster eh?

I don't read the forums much, usually just the headlines.

A friend IM'd me with the info a few mins before I started this thread.
goBigtime is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-09-2005, 07:11 PM   #7
goBigtime
Confirmed User
 
Join Date: Nov 2002
Posts: 7,761
Quote:
Originally Posted by e-god
as firefox is getting more popular more exploits are being found, waiting till nerds will start to write malicious viruses and worms that will go thru firefox
With firefox, If they don't write and exploit them within an hour of the exploit being released then they'll probably be too late :P
goBigtime is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.