View Single Post
Old 29-08-2005   #126 (permalink)
Nemesys
CDFreaks Resident
 
Nemesys's Avatar
 
Join Date: Jun 2002
Location: Florida, USA
Posts: 1,079
Re: Why You Should Dump Internet Explorer

Quote:
Originally Posted by EyeForOne

The International Character exploits have long been fixed in Moz/FF , since it was first learned of - it was a swift, fast, small, and easy fix - unlike most ms fixes, that linger for years before they're attended to....but that doesn't mean those who are savvy, can't use IE reliably, nor should they change if they are happy with it. It's the NEW users that have no clue, that continue to allow the proliferation of nasties ...and NEW systems that should have alternative browser/s as a choice IMO, such as when Netscape 4.06 and IE4 were bundled together (but that's when the Java VM peaked as a real proprietary mess)

I wasn't going to post at all - but that Chinese "BIG5" Character Encoding was glaringly obvious, I thought I'd mention it.


If the exploit was fixed then the page would not display the Secunia site. All firefox has done is change the way the address bar displays the address. It displays it in Punycode which identifies the exploit, but the average user does not know this and would still respond to the displayed page.

Having the address bar display http://www.xn--paypl-7ve.com/ instead of http://www.paypal.com is not a fix as long as you are still taken to the same location. As long as the Secunia site is displayed the browser has been spoofed, regardless of what the address bar displays.

Punycode
Attached Images
File Type: gif ffspoof.gif (57.4 KB, 160 views)
__________________
Case: Chieftec Dragon Golden Blue DX-01BLD-U Server Chassis Motherboard: ABIT IP35 Pro CPU: Intel Core 2 Duo E8400 3.0GHz @ 4.0GHz (Tuniq Tower 120 CPU Cooling) RAM: 2GB Crucial Ballistix PC-8500 DDR2 1066 Video Card: GeForce 7900GT 256MB PCI Express x16 Sound Card: SoundBlaster Audigy ES Monitor: Hanns-G HW-223DPB (22” LCD) Audio System: MASSIVE NIC: Dual Realtek Gigabit Ethernet Controller
DVD-RAM: Samsung SH-S203B SB04
DVD-RAM: Lite-On LH-20A1L BL06
Hard Drive (Internal Storage): Seagate Barracuda 500GB SATA II File Storage
Hard Drive (Removables): (3) LIAN-LI SATA Mobile Racks
Drive #1. Seagate Barracuda 320GB SATA II WIN XP Professional
Drive #2. Seagate Barracuda 320GB SATA II WIN Vista Ultimate
Drive #3. Seagate Barracuda 80G SATA II Testing


http://valid.x86-secret.com/show_oc.php?id=364264
Nemesys is offline   Reply With Quote