Slashdot Mirror


Shmoo Group Finds Exploit For non-IE Browsers

shut_up_man writes "Saw this on Boing Boing: East coast hacker con Shmoocon ended today and they had a nasty browser exploit to show off... using International Domain Name (IDN) character support to display fake domain names in links and the address bar. Their examples use Paypal (with SSL too) and this looks very useful for phishing attacks. Interesting note that it works in every browser *except* IE (which makes this exploit a lot less dangerous in the end, I suppose)."v The reason IE isn't vulnerable is because it doesn't natively support IDN; with the right plug-in, it too is vulnerable.

1 of 621 comments (clear)

  1. Re:notepad by Evil+Adrian · · Score: 0, Flamebait

    They didn't implement something that fucks everyone else over, and yet you still manage to find a way to spin it to try to make Microsoft look bad.

    Just admit it -- Microsoft got it right. You don't have to cry about it, it'll be ok.

    --
    evil adrian