Boing Boing: Shmoo Group exploit: 0wn any domain, no defense exists

Boing Boing: Shmoo Group exploit: 0wn any domain, no defense exists:

"Shmoo Group exploit: 0wn any domain, no defense exists Pablos sez, 'Shmoocon ended today. And just to prove The Shmoo Group wasn't sitting on their asses for the entire time while planning the con - A new exploit was demo'd by EricJ that left all jaws our on the floor. Want to own ANY domain? Want a trusted SSL cert for it? Check it out here. We 0wnz0rd PayPal, but left the rest for you. We have no idea how to fix this and neither do the browser developers. Official advisory here. Phishing attacks of doom coming soon.' Link (Thanks, Pablos!)"

The author claims it works in everything except IE. I tested it on my Mac today, and it doesn't work in NetNewsWire, though it works with Safari, which is weird.

One Boing Boing reader gives a workaround for users of Firefox:

1) Goto your Firefox address bar. Enter about:config and press enter. Firefox will load the (large!) config page.

2) Scroll down to the line beginning network.enableIDN -- this is International Domain Name support, and it is causing the problem here. We want to turn this off -- for now. Ideally we want to support international domain names, but not with this problem.

3) Double-click the network.enableIDN label, and Firefox will show a dialog set to 'true'. Change it to 'false' (no quotes!), click Ok. You are done.

4) Go check out the shmoo demo again and notice it no longer works.

I hope Apple will do something about this in Safari.

No TrackBacks

Un gros trou de sécurité dans nos navigateurs, semble-t-il. Pour une fois, les utilisateurs de IE ne semblent pas avoir de soucis à se faire. Ne cliquez jamais sur les liens dans vos e-mails.... Read More

Pour une fois, le mauvais élève IE est le seul épargné pour n’avoir pas pris le temps de s’adapter à la norme IDN. Et il semblerait qu’elle comporte une faille, que dis-je, un gouffre de sécu... Read More

Leave a comment

mensuelles Archives

Recent Entries

  • On Apple Safari's use of justified text in Reader

    On my professional blog, a take on Apple Safari's use of justified text in Reader....

  • Curated computing

    Perhaps the most pernicious proposition of the “everything must be open” crusade is the notion that curation is bad and anti-freedom. Soldiers of this crusade...

  • Death by Apple, the obsolescence of Flash

    Flash was created during the PC era – for PCs and mice. Flash is a successful business for Adobe, and we can understand why they...

  • Ogg (and Mozilla) objections

    Ogg objections by Måns: When challenged, three types of reaction are characteristic of the Ogg campaigners. On occasion, these people will assume an apologetic tone,...

  • Paris Web 2010 — Call for speakers

    (Disclaimer: I manage the communication for Paris Web, this is a copy of the official call for speakers.) Hello all, Paris Web is a French...