Go Back   FlashFXP Forums > FlashFXP > Release Archive > Website

Website Comments, Suggestions, Questions, Concerns, Fan mail, Hate mail, Whatever goes.

 
 
Thread Tools
Old 02-07-2005, 11:21 AM   #1
Posse Member
Ultimate Scripter
ioFTPD Administrator
 
Join Date: Dec 2002
Posts: 2,022
Default New browser exploit - all browsers affected (except IE!)

Nothing ioFTPD-related, but I think this is big enough to warrant a post here:

New exploit that works in all browsers (Safari, Opera, Firefox, etc.) but not IE(!)
http://www.boingboing.net/2005/02/06..._exploit_.html

Scary.
Especially with no known (working) fix...
(The Firefox suggested fix doesn't work.)
Mouton is offline  
Old 02-07-2005, 05:33 PM   #2
Senior Member
FlashFXP Beta Tester
ioFTPD Scripter
 
Join Date: Sep 2002
Posts: 558
Default

And Maxthon which is way better then ie anyway. It is more like IE on super steroids..
Popupblocker, tabbed windows, skins, loads and loads of plugins etc...
FTPServerTools is offline  
Old 02-07-2005, 10:22 PM   #3
Senior Member
ioFTPD Foundation User
 
Join Date: Oct 2003
Posts: 424
Default

Maxthon uses IE's engine (thus it's not affected).
wooolF[RM] is offline  
Old 02-08-2005, 10:08 AM   #4
Posse Member
Ultimate Scripter
ioFTPD Administrator
 
Join Date: Dec 2002
Posts: 2,022
Default

For Safari users: The new version of Saft (and the new free Saft Lite) offers a warning box dialog until Apple can fix the browser proper. http://haoli.dnsalias.com
Mouton is offline  
Old 02-08-2005, 03:17 PM   #5
Senior Member
ioFTPD Scripter
 
Join Date: Feb 2003
Posts: 469
Default

The firefox fix works for me.
SnypeTEST is offline  
Old 02-08-2005, 09:00 PM   #6
Senior Member
ioFTPD Foundation User
 
Join Date: Oct 2003
Posts: 424
Default

Works? o.O Bug is still marked as not fixed...

Were u talking about that "fix" with compreg.dat? It's not a very good solution anyway as the file gets regenerated each time you install/reinstall new extension... And disabling all idn service lookups isn't great either...
wooolF[RM] is offline  
Old 02-08-2005, 09:01 PM   #7
Posse Member
Ultimate Scripter
ioFTPD Administrator
 
Join Date: Dec 2002
Posts: 2,022
Default

Safari's Saft got the right way to handle this I think... popup a dialog when a phishing attack is probable. User can then decide if it's a valid IDN or not.
Mouton is offline  
Old 02-08-2005, 09:16 PM   #8
Senior Member
ioFTPD Foundation User
 
Join Date: Oct 2003
Posts: 424
Default

Weird that FF/Mozilla devs haven't fixed this yet. Usually they are pretty fast
wooolF[RM] is offline  
Old 02-09-2005, 12:16 AM   #9
Senior Member
FlashFXP Beta Tester
ioFTPD Scripter
 
Join Date: Aug 2003
Posts: 521
Default

The 'bug' actually lies in the standard, the affected browsers can only be blamed for correctly implementing this (bad) standard. IE gets away with it because it's outdated and didn't implement it yet
ADDiCT is offline  
Old 02-09-2005, 12:53 AM   #10
Member
FlashFXP Registered User
 
Join Date: Feb 2003
Posts: 66
Default

Quote:
Originally posted by ADDiCT
The 'bug' actually lies in the standard, the affected browsers can only be blamed for correctly implementing this (bad) standard. IE gets away with it because it's outdated and didn't implement it yet
Exactly, It has it advantages to be 3 years behind the competition.
Bratell is offline  
Old 02-14-2005, 04:07 AM   #11
Senior Member
ioFTPD Foundation User
 
Join Date: Oct 2003
Posts: 424
Default

Finally some solututions for my fav browser - Firefox!

Disable IDN support in firefox, for good:
http://friedfish.homeip.net/extensions/no-idn.xpi

Trustbar for firefox - shows punycoded IDN, and allows for better SSL management
http://trustBar.mozdev.org
wooolF[RM] is offline  
 
Create a free account to browse our forums without ads



Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Compare Folder Content -- SUBDIRS too? dgrrr General Discussions 1 04-04-2005 08:28 PM
How to write this script shawn1 General Discussions 0 10-30-2004 02:13 PM


All times are GMT -5. The time now is 01:46 AM.