FIXIT MENU:
home about us contact us

WHAT'S AVAILABLE:
free scripts advanced scripts online tools great books web related tutorials contributed tutorials news archive geek toys!

SUPPORT:
help forum live chat help



Selected article

RSS feed   enewsbar Live Subscribe    Add to MyYahoo    Add to Google

Other HTMLfixIT articles:




by yomcat

Take a look at http://www.shmoo.com/idn/
The link is “http://www.pаypal.com/”, which the browsers punycode handlers render as www.xn--pypal-4ve.com.
This security flaw could be quite major, as any letter can be replaced by its look-alike from an international character script. For full details, take a look at this file.

Vulnerable browsers include (but are not limited to):

Most Mozilla-based browsers (Firefox 1.0, Camino .8.5, Mozilla 1.6, etc)
Safari 1.2.5
Opera 7.54
Omniweb 5

While those are mainly Mac browsers (OmniWeb and Safari), all users of anything that isn’t IE should be wary, at least until a patch is released which fixes this issue.

Update: (Franki) There is a temp fix for Firefox already out, I’ve tried it and it works. Here are the steps:
1. Go to your Firefox address bar and enter: about:config and press enter, this will bring up Firefox’s internal configuration page.
2 Scroll down to the line beginning: network.enableIDN or in the alternative enter that phrase (you can cut and paste it) into the filter text box and click “show all”.
3 Double-click the network.enableIDN label, and Firefox will change the default value of ‘true’ to ‘false’, close that window and you’re done.

There will no doubt be a software fix on the way soon, so you should run Firefox update regularly. (Go to “tools”->”options” -> “advanced” and scroll down till you see the section called “Software Update” and click “Check now” and Firefox will do the rest.

It should be noted that the reason that IE is not vulnerable, is because they never supported international domains in the first place. There is a plug in to enable that functionality in IE, and if you have the plug-in installed, then your copy of Internet Explorer is just as vulnerable.
Read more on this issue here.








Comments are closed.







This site is totally free to use, you have absolutely no moral or legal obligations to help us continue.
There are however, some costs involved in running the site.

<random humor>
Plus Don's kid is a good runner and she goes through sneakers fast.
</random humor>

So if this site helped you find your way, perhaps you could consider contributing to our costs. Whatever amount you feel this site was worth to you would be just wonderful.
Use PayPal if you do decide to share and help us with the costs and in appreciation for our time and attention, or alternatively buy a book from our Bookstore..


  Time  in  Don's  part  of the world is:   November 23, 2024, 7:01 am
  Time in Franki's part of the world is:   November 23, 2024, 8:01 pm
  Don't worry neither one sleeps very long!



privacy policy :: support us :: home :: live chat help
contact us :: forum ::tutorials :: bookstore :: Site Map



      Valid XHTML 1.0!             powered by Apache Server
Pic 3 Pic 3

SEARCH:
USEFUL LINKS:

CIGHTML Firefox Thunderbird ClamWin WordPress SpyBot S&D TheGIMP Apache for Windows Registry Cleaners More cool stuff:

//-->

HTMLfixIT Site Stats.

Browser Statistics
Internet Explorer 85.88%
IE 717.63%
IE 62.3%
IE 50.00%
IE other8.6%
Moz Firefox 3.x3.03%
Moz Firefox 2.x0.18%
Moz Firefox 0.x/1.x26.65%
Netscape 8.x0.00%
NS 6+/Mozilla2.73%
Moz Seamonkey0.00%
K-meleon0.00%
Epiphany0.00%
Netscape 4.x0.00%
Opera 9.x0.00%
Opera 8.x0.00%
Opera 7.x0.42%
Opera 6.x0.00%
Opera other0.42%
Safari Mac/Intel5.21%
Safari Mac/PPC0.06%
Safari Windows25.2%
Google Chrome1.51%
Konqueror0.18%
Galeon0.00%
WebTV0.00%


Resolution Statistics
640 x 4800.25%
800 x 60026.14%
1024 x 76836.55%
1152 x 8640.25%
1280 x 80011.68%
1280 x 8540.00%
1280 x 102417.01%
1400 x 10500.00%
1600 x 12001.02%
1920 x 12007.11%
2560 x 10240.00%


OS Statistics
Windows 741.55%
Windows Vista2.4%
Windows 20033.91%
Windows XP20.86%
Windows 20000.36%
Windows NT40.05%
Windows 98/ME0.05%
Windows 950.00%
Linux/UNIX/BSD8.76%
Mac OSX8.03%
Mac Classic0.00%
Misc14.03%



New Windows Virus Alerts
also by sophos.

17 Apr 2011 Troj/Mdrop-DKE
17 Apr 2011 Troj/Sasfis-O
17 Apr 2011 Troj/Keygen-FU
17 Apr 2011 Troj/Zbot-AOY
17 Apr 2011 Troj/Zbot-AOW
17 Apr 2011 W32/Womble-E
17 Apr 2011 Troj/VB-FGD
17 Apr 2011 Troj/FakeAV-DFF
17 Apr 2011 Troj/SWFLdr-W
17 Apr 2011 W32/RorpiaMem-A

For details and removal instructions, click the virus in question.