.com.unity Forums
  The Official e-Store of Shrapnel Games

This Month's Specials

Raging Tiger- Save $9.00
winSPMBT: Main Battle Tank- Save $5.00

   







Go Back   .com.unity Forums > Shrapnel Community > Space Empires: IV & V

Reply
 
Thread Tools Display Modes
  #1  
Old February 8th, 2005, 01:14 AM
Sivran's Avatar

Sivran Sivran is offline
Sergeant
 
Join Date: Dec 2003
Posts: 251
Thanks: 0
Thanked 0 Times in 0 Posts
Sivran is on a distinguished road
Default OT: Important Security Issue in Non-IE browsers

Ironically IE is NOT affected by this vulnerability.

...but then unless it has the plugin for it, it doesn't support this anyway!

Thread at DSLReports Security: The state of homograph attacks

Brief Summary: browsers supporting Punycode/IDN are vulnerable to a URL spoofing attack that can easily fool less sophisticated and complacent users. The address bar will contain the expected url (in text, not an image even!) and even the https: protocol and lock icon can be spoofed.

The most disturbing part of the story is this: (emphasis mine)
Quote:

VI. Vendor Responses

Opera: They believe they have correctly implemented IDN, and will not be making any changes.



Proof of concept link:
http://www.shmoo.com/idn/

There is a workaround for Mozilla browsers but it only partially works. In the meantime I suggest you type in/use a bookmark and never click links in emails. As for Opera users, show your displeasure by pirating...oh wait, I mean, by switching to Mozilla.
Reply With Quote
  #2  
Old February 8th, 2005, 10:57 AM
Spoo's Avatar

Spoo Spoo is offline
First Lieutenant
 
Join Date: Jan 2001
Location: Toledo, OH
Posts: 641
Thanks: 0
Thanked 0 Times in 0 Posts
Spoo is on a distinguished road
Default Re: OT: Important Security Issue in Non-IE browser



The fix for Firefix is pretty simple. Type aboutfig in the address bar. Scroll down until you see network.enableIDN then double-click it to change the value to false. This shouldn't hurt anything, since IE doesn't support this feature anyway (and the internet is IE-biased).
__________________
Assume you have a 1kg squirrel
E=mc^2
E=1kg(3x10^8m/s)^2=9x10^16J
which, if I'm not mistaken, is equivilent to roughly a 50 megaton nuclear bomb.
Fear the squirrel.
Reply With Quote
  #3  
Old February 9th, 2005, 12:22 AM
Sivran's Avatar

Sivran Sivran is offline
Sergeant
 
Join Date: Dec 2003
Posts: 251
Thanks: 0
Thanked 0 Times in 0 Posts
Sivran is on a distinguished road
Default Re: OT: Important Security Issue in Non-IE browser

As noted in the DSLReports thread, that workaround doesn't work correctly. The behavior doesn't stick, although the setting does still appear. It will hopefully be soon fixed.

There is another workaround for Mozilla browsers that involves editing another file. This post contains it. Also see this one.

There we go.

There's also a Proxo filter that Proxomitron users can add: This one
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump


All times are GMT -4. The time now is 10:44 AM.


Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Copyright ©1999 - 2025, Shrapnel Games, Inc. - All Rights Reserved.