Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > Applications > Safari Exploit & temp fix

Safari Exploit & temp fix
Thread Tools
Professional Poster
Join Date: Jan 2001
Location: Manchester,UK
Status: Offline
Reply With Quote
Feb 8, 2005, 06:06 PM
 
New Safari (and Mozilla, Firefox) domain name spoofing vulnerability
This is a DNS/IDN thing and effects most browsers except IE, because they hadn't go around to implementing IDN yet.
A detailed explanation and unofficial temp fix is available here on MacFixIt.
     
Mac Enthusiast
Join Date: Oct 2003
Location: .no
Status: Offline
Reply With Quote
Feb 9, 2005, 05:27 AM
 
The new version of Saft also fixes this.

     
Mac Elite
Join Date: Mar 2001
Location: CO
Status: Offline
Reply With Quote
Feb 9, 2005, 06:39 AM
 
I thought it disconcerting that (as pointed out by Kee Hinckley in MacFixit forums:

'I have to say I'm pretty disappointed in the browser writers on this one. This
issue was raised from the very moment that the IDN system was proposed.
It's mentioned in the standards (RFC3490):

"To help prevent confusion between characters that are visually
similar, it is suggested that implementations provide visual
indications where a domain name contains multiple scripts. "

Perhaps the recommendation should have been stronger, but anyone who has
even casually followed the standards process should have been aware of the
issue." '
TOMBSTONE: "He's trashed his last preferences"
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 11:43 AM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2