Browser/Phishing Exploit

Anyone who uses a modern, non-:IE: browser (Firefox, Mozilla, Safari, etc.) should go check out this post on Boing Boing about a new exploit.  It is a hole opened by the browsers’ support of the International Domain Name (IDN) feature; it allows someone to spoof a domain name and send the user somewhere else.  With the rapid growth of phishing attacks recently, this is actually a fairly serious threat.

For Mozilla/Firefox/Gecko users, the Boing Boing post linked above has a way to disable the feature that allows this exploit.

This is an older entry and as such, it may be by a guest author or contain formatting problems / extraneous code. If you notice something wrong with the entry, please use the Contact page to let me know the entry title and issue.

Comments

Ew, thanks for sharing.  BoingBoing’s not been on my regular browsing ring for some time, so I would have had to catch this news somewhere else I guess.

Leave Your Comment