.com.unity Forums
  The Official e-Store of Shrapnel Games

This Month's Specials

Raging Tiger- Save $9.00
winSPMBT: Main Battle Tank- Save $5.00

   







Go Back   .com.unity Forums > Shrapnel Community > Space Empires: IV & V

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #1  
Old February 8th, 2005, 01:14 AM
Sivran's Avatar

Sivran Sivran is offline
Sergeant
 
Join Date: Dec 2003
Posts: 251
Thanks: 0
Thanked 0 Times in 0 Posts
Sivran is on a distinguished road
Default OT: Important Security Issue in Non-IE browsers

Ironically IE is NOT affected by this vulnerability.

...but then unless it has the plugin for it, it doesn't support this anyway!

Thread at DSLReports Security: The state of homograph attacks

Brief Summary: browsers supporting Punycode/IDN are vulnerable to a URL spoofing attack that can easily fool less sophisticated and complacent users. The address bar will contain the expected url (in text, not an image even!) and even the https: protocol and lock icon can be spoofed.

The most disturbing part of the story is this: (emphasis mine)
Quote:

VI. Vendor Responses

Opera: They believe they have correctly implemented IDN, and will not be making any changes.



Proof of concept link:
http://www.shmoo.com/idn/

There is a workaround for Mozilla browsers but it only partially works. In the meantime I suggest you type in/use a bookmark and never click links in emails. As for Opera users, show your displeasure by pirating...oh wait, I mean, by switching to Mozilla.
Reply With Quote
 

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump


All times are GMT -4. The time now is 09:11 PM.


Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Copyright ©1999 - 2025, Shrapnel Games, Inc. - All Rights Reserved.