You are here: silicon.com > Networks > WebWatch

WebWatch

Firefox update plugs phishing hole

Version 1.0.1 now available...

By Stephen Musil

Published: 28 February 2005 09:00 GMT

The Mozilla Foundation released on Thursday an update to the Firefox web browser to fix several vulnerabilities, including one that would allow domain spoofing.

The open-source project released Firefox 1.0.1 to fix, among other bugs, a vulnerability in the Internationalised Domain Names (IDN), a standard for handling special character sets in domain names that lets companies register domain names that appear to be the same in different languages. The update is available from the Mozilla.org website.

The IDN vulnerability allowed an attacker to create a fake website on a non-Microsoft browser in order to pull off a phishing scam. A spoofed link would seem to be a legitimate URL in the address bar of affected browsers. But instead of taking the victim to the trusted site, the link would lead to a phoney website with a domain rendered as the same address under the IDN process.

The updated browser will display the IDN Punycode in the address bar, preventing URL spoofing. Punycode is the encoding of Unicode strings into the limited character set supported by the Domain Name System and IDN.

Chris Hofmann, director of engineering for the Mozilla Foundation, said in a statement: "Regular security updates are essential for maintaining a safe browsing experience for our users."

Phishing attacks, which try to fool consumers into handing over sensitive information by creating legitimate-looking websites and email messages, have become a central security concern recently. While vulnerabilities in Microsoft's Internet Explorer have been the focus of much of the concern, other browsers also have had their fair share of flaws.

The update is available for Windows, Mac OS X and Linux at Mozilla.org.

Firefox recently surpassed 25 million downloads, achieving that mark in 100 days. Mozilla, which released the free 1.0 program in November, said an average of 250,000 people download Firefox every day and more than half a million websites feature Firefox promotions.

Mozilla, an open source software foundation formed by Netscape, was spun off from Time Warner in 2003.

Stephen Musil writes for CNET News.com.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure
Read and write about internet access at the airports of the world at atlarge.com. Rate airports, and see what others have to say...

Natasha Lomas Exclusive: Jimmy Wales on what's next for Wikipedia Why Wikipedia needs geeks and why a life unplugged is unthinkable

Peter Cochrane Peter Cochrane's Blog: United breaks guitars? Customer service has changed forever


  • Jobs
Web Applications Vulnerability Tester

You will also have reasonable coding experience and be able to check code for vulnerabilities before it is released. You will conduct regular ...

Software Project Manager - London - Up to 65K

Software Project Manager London SE1 Up to 65,000 As a leading provider of domain names and Internet-related services, our client has registered ...

Web Developer - London - XHTML - CSS - JAVA - AJAX

The candidate will posess: • Excellent communication skills • Excellent documentation skills • Excellent time management skills ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: