Firefox IDN workaround
Few, who are interested in security, can have failed to miss the IDN issue that most up to date browsers support (not IE obviously). Basically IDN (RFC3490 I think) allows none ASCII characters to be used in domain names but, it was recently pointed out, this can be used to spoof URLs - very nasty.
Anyway for now, until Mozilla come up with a better solutiuon, we have a work around. This basically involves turning of IDN functionality. To do so in Firefox, just go to about:config and scroll down to network.enableIDN and double click until it says "false". Not an ideal situation but I cant really see myself ever needing to visit a site that uses this technology at the moment and so Im happy to disable it.
Make no mistake, leaving this vulnerability open may well have very serious repercussions.

2 Comments:
great tip Ade - have disabled it immediately in my browser. What worries me the post is how simple it is - for those who don't believe that, do this .
Well at least IE is also vulnerable in this area!
By
Anonymous, at 12:32 am
I totally agree, and how many people will take the steps you and I have, to disable it, even though it is quite easy to do so?
Have a look at my next post for something just as bad!
By
Ade, at 10:10 pm
Post a Comment
<< Home