Chat or Talk in the INReview Discussion Forum Chat or Talk in the INReview Discussion Forum
Support INReview. Please visit our sponsors and shop.
 
register chat shopping members links refer search home
INReview INReview > The Scuttlebutt Lounge > Computers & Internet > Scams, Frauds and Virus Threats > Serious Spoofing Scam Affects Most non-IE Browsers
Search this Thread:
  Print Version | Email Page | Bookmark | Subscribe to Thread
Author
Thread Post New Thread   
Gold Member
Crazie
Republican :D

offline
Registered: Nov 2003
Local time: 03:47 AM
Location: Texas
Posts: 958

Serious Spoofing Scam Affects Most non-IE Browsers post #1  quote:



Boing Boing has reported a technique which allows phishers to
fake domain names in email links, the address bar and SSL
certificate of almost all browsers other than Internet Explorer.
The scam utilizes features of IDN, the industry standard for
representing non ASCII characters in domain names, to substitute
non standard characters for very similar looking English
characters. This newsletter is plain text so I can't give you an
example but substituting and '0' for an 'O' in SUPPORTALERT.COM
vs. SUPP0RTALERT.COM will give you the idea. IE does not comply
with the standard and is consequently not affected. Apparently
Mozilla incorporated a fix into nightly builds within 12 hours
which allows users to turn off IDN but there is no patch yet for
released versions of Mozilla or FireFox. However, a developer
has patched the FireFox SpoofStick extension so that it will
reveal the scam. More generally the problem can be avoided by
not clicking on links nor cutting and pasting but rather typing
them in to your browsers address bar by hand. All this supports
my current view that you can no longer reliably pick phishing
scams. If you get an email from a bank or financial institution
requesting some action then phone first, act latter.
http://www.boingboing.net/2005/02/0...p_exploit_.html
http://secunia.com/multiple_browsers_idn_spoofing_test
http://www.jarnot.com/mt/archives/2...fox_spoof_s.php



"The American Revolution was fought for a reason." ~~ Director of Clark County's board of elections
Old Post 02-21-2005 05:31 PM
Click here to Send Crazie a Private Message Find more posts by Crazie Add Crazie to your buddy list Crazie's ICQ status Send an AIM message to Crazie Crazie's MSN ID is craziejuggalo@msn.com Click Here to Ignore Crazie REPORT this Post to a ModeratorNOMINATE this Post for Reward Points Reply w/Quote
Time: 08:47 AM Post New Thread   
  Print Version | Email Page | Bookmark | Subscribe to Thread
INReview INReview > The Scuttlebutt Lounge > Computers & Internet > Scams, Frauds and Virus Threats > Serious Spoofing Scam Affects Most non-IE Browsers
Search this Thread:
Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is OFF
vB code is ON
Smilies are ON
[IMG] code is ON
Forum Policies Explained
 
Rate This Thread:

< - INReview.com >

Copyright ©2000 - 2007, Jelsoft Enterprises Limited
Page generated in 0.22782397 seconds (92.33% PHP - 7.67% MySQL) with 44 queries.

ADVERTISEMENTS
Support This Site! Shop @ INReview!


© 2007, INReview.com.   Popular Forums  My Favorites All Forums   Web Hosting and Web Design by Psyphire.
INReview.com: Back to Home