republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Update on the IE vulnerability
Search Topic:
view: topics flat text 
Post a:

Comments on news posted 2003-12-12 11:28:01: An update on the recently reported IE vulnerability that lets people create fake sites that look real and disguise their true address. You can see the bug in action using this hoax site: here (designed by us). ..

page: 1 · 2 · 3 · 4
AuthorAll Replies


borborpa
Slipping Slowly Into Oblivion
Premium
join:2002-02-20
New Cumberland, PA
clubs:
Another reason to use Firebird...



Amaethon

join:2000-10-22
USA
clubs:
No fix yet eaither.. shessh

youngmoore

join:2001-03-16
Marietta, GA
·Sprint Mobile Broa..

this is what I get from firebird
»www.symantec.com%2Fanything%2FI%···dex.html

from IE
»www.symantec.com/anything/I/want···ut/here/

Interesting

From my understanding you can clock the URL line to just about anything you want. I use that for our webmail so it just shows the hostname not the IP.

ym


Xtract

join:2003-04-25
Etheria
reply to Amaethon
I loaded firebird when I read the first article and have not touched IE since.


tons of fun

join:2002-10-11
Rochester, NY
 K-Meleon

Another reason to use K-Meleon!!

Be well all........& safe!


raw
War Eagle
Premium
join:2001-01-17
Madison, AL
clubs:

said by tons of fun See Profile:
Another reason to use K-Meleon!!
Or Firebird, Epiphany, Konqueror, Galeon, or even stock Mozilla. Heck, anything is safer than IE at this point.
--
[BBR]raw
America's Army
BBwc Enemy Territory clan founder


ifarrell

join:2000-08-10
Willow Spring, NC
IE Out.....

I only use IE for Windows Updates and for the few web sites that don't support Firebird that I need access to. I inform the Webmasters in cases like that though.


woody7
Premium
join:2000-10-13
Torrance, CA
·EarthLink
·DSL EXTREME

reply to Xtract
Re: Another reason to use Firebird...

said by Xtract See Profile:
I loaded firebird when I read the first article and have not touched IE since.

Been using it for a long time now and only use IE for updates........have been a happy camper since
--
Bloome


Matt
Take me down to the paradise city
Premium
join:2003-07-20
Jamestown, NC
Ummm......

Ok, so IE shows the proper / and Firebird shows the improper HTML escape code, %2F.

Sounds like a Firebird bug to me.
--
Edwards in 2004


vice8686

join:2000-10-13
Lancaster, CA
 reply to tons of fun
Re: K-Meleon

Thanks for mentioning the K-Meleon browser. I like it so far. It's also nice and fast:)


Mike
Premium,Mod
join:2000-09-17
Pittsburgh, PA
clubs:
reply to Matt
Re: Ummm......

Safari does the same thing.. that's kind of the way it's typed if you looked at the code..


Trel
Good Evening
Premium
join:2002-10-08
Hillsborough, NJ

put the practicle joke potential

isn't it also funny to claim that you hijacked say google if you do something like this

»www.krahs-emag.com/?page=owned2&···orts.com
--
My teacher asked the square root of Pi. I thought the answer was 2 slices.


deltat2000
Timor Omnis Abesto
Premium
join:2000-04-13
127.0.0.1
clubs:

reply to borborpa
Re: Another reason to use Firebird...

Okay...........now that you have me totally paranoid..whats the real url/link to Opera or Firebird?

Hopefully Justin will post it.......I think I'de trust his links...

deltat2000 softly whistles in the dark! and thinks "boy its getting kinda scary online"
--
"Lets Roll" You are missed Todd.The Future Is Purchased By The Present!Lifetime member VRWC


Jason Levine
Premium
join:2001-07-13
USA

Microsoft's Advice

said by From BetaNews.com:
In the meantime, before a fix is released and while industry pundits argue over proper disclosure, Microsoft advises its customers to follow its "Protect Your PC" guidance program by enabling a firewall, installing all available product updates and employing anti-virus software.
What type of advice is this? Granted, it's good to do all of those things, but that won't stop this particular bug. If a faked out site gets you to submit your personal information then none of those protective measures will stop the data from falling into a hacker's hands. If the faked out site gets you to download and run a program (by exploiting the trust and reputation of the site it's pretending to be), your firewall might alert you, but you would be just as likely to let it through. (After all, it came from a site you know and trust... or so you were tricked into thinking.)

The best advice is don't click on links in unrequested communications.

(Ok, that and perhaps don't use IE, but that's not an option for me. As a web developer, I have to use whichever browser my audience is using, and this means IE for me.)
--
-Jason Levine
http://www.jasons-toolbox.com/
http://www.PCQandA.com/
http://www.urateit.com/


Xtract

join:2003-04-25
Etheria
reply to deltat2000
Re: Another reason to use Firebird...

Use good old google

marcussen

join:2003-02-20
Shawnee, OK
·Allegiance Communi..

No problems with Avant Browser

I use the Avant browser which uses IE as a base but this problem shows up in the address bar making it clear what the address realy is, it also adds pop-up blocker and tabbed browsing, ( »www.avantbrowser.com/ )


AlexNYC

join:2001-06-02
Edwards, CO

 Opera

Here's what Opera is saying:


Vamp
5c077
Premium
join:2003-01-28
MD
·Verizon FIOS

Same thing here, in opera it reads the true address of "http://www.symantec.com@i.dslr.net/symantec/www.symantec.com/index.html"

And also gives the warning..
--
Best game ever > »www.desertcombat.com

SanJoseNerd
Premium
join:2002-07-24
San Jose, CA

reply to AlexNYC
That looks like the right way to handle it.

Even if the MSIE address bar gets corrected, the problem isn't really fixed. Many legitimate ecommerce sites show long strings of letters and symbols following the URL. So even if the @i.dslr.net... were displayed, many users would ignore it.

MSIE needs to issue a specific warning, like that Opera dialog box.


Matt
Take me down to the paradise city
Premium
join:2003-07-20
Jamestown, NC
·North State Commun..

reply to Mike
Re: Ummm......

said by Mike See Profile:
Safari does the same thing.. that's kind of the way it's typed if you looked at the code..

It should be typed that way in the code, otherwise the / might be interpreted as an HTML command, instead of actually displaying the correct character.

So, in that sense, IE is correct in the way it is displaying things.

The part that is INCORRECT and sloppy programming on Microsoft's part, is they should have LIMITED it to only a certain set of characters instead of parsing EVERY escape/control code.
--
Edwards in 2004
Forums » Update on the IE vulnerabilitypage: 1 · 2 · 3 · 4


Wednesday, 25-Nov 22:48:46 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF