
Firefox and Opera at risk but IE doesn't have vulnerability... This time...
By Robert Lemos
Published: 8 February 2005 09:05 GMT
A security weakness in a standard for handling special character sets in domain names could let an attacker spoof websites on non-Microsoft browsers, a researcher has warned.
Security expert Eric Johanson said at the ShmooCon hacker convention last weekend that the problem arises because certain browsers support a standardised way of representing domain names in the letters or characters of any language. Called Internationalised Domain Names, the standard allows companies to register domain names that appear to be the same in different languages.
That encoding scheme could enable an attacker to create a fake website for a phishing scam. A spoofed link would seem to be a legitimate URL in the address bar of affected browsers - Opera, Apple's Safari, and the Mozilla and Firefox browsers from the Mozilla Foundation. But instead of taking the victim to the trusted site, the link would lead to a phoney website with a domain rendered as the same address under the IDN process.
Chris Hofmann, director of engineering at Mozilla, said in a statement the Mozilla Foundation is looking for a long-term solution to the issue.
"With the increase in phishing attacks, there is a growing concern that exploits could take advantage of this feature to trick users into visiting rogue sites," Hofmann stated. "Mozilla is looking at options for fixing or disabling this feature and should have more information available very soon."
Phishing attacks, which try to fool consumers into handing over sensitive information by creating legitimate-looking websites and email messages, have become a central security concern recently. While vulnerabilities in Microsoft's Internet Explorer have been the focus of much of the concern, other browsers also have had their fair share of flaws.
The security weakness in the IDN scheme comes as registrars push for support for expressing domain names in different languages and scripts.
"There are now many ways to display any domain name on a browser, as there are a huge number of [character sets] which look very similar to Latin (characters)," Johanson said in an advisory.
The advisory demonstrates the attack using the domain for PayPal, but using an alternate Unicode character for the first "a". That gives an address that looks like "http://www.pàypal.com," but with a smaller "a".
Details of the flaw were shown at ShmooCon, a hacking and computer security convention, in Washington D.C., last weekend. The Shmoo Group, a loose association of security professionals that runs the convention, notified the affected browser makers in mid-January. Johanson is a member of the Shmoo Group.
Apple, VeriSign and Opera could not immediately be reached for comment.
Microsoft has not implemented support for IDN yet, so its IE browser is not vulnerable to the flaw.
Browser security is gaining attention among software makers. In December, internet security company Netcraft released an IE plug-in that it said could help people avoid becoming victims of online fraud. In addition, Netscape announced last month that it is getting ready to release a browser designed to resist phishing attacks.
Robert Lemos writes for CNET News.com.
The ability to code in JavaScript, CSS and Flash would be advantageous but not essential.You must test your web sites for functionality in all ...
Proficiency in a variety of programming as a prerequisite Delphi 6 - 2006, with other development languages being advantageous including :- languages ...
Clients range from household names such as Dell and Anadin, to leading business to business firms. You will need to have a background in developing ...
Agenda Setters 2008
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Rob Bamforth Seeking memorable mobile apps Quocirca's Straight Talking: Why are there so few?
Stewart Baines How much SEO is too much? Net Effect: Plus 10 tips on boosting your site's profile