Firefox browser security flaw fixed

Moderators: Moderator, Global Moderator

Post Reply
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Firefox browser security flaw fixed

Post by Tami »

Firefox browser security flaw fixed
By PETER SVENSSON

NEW YORK — A new version of the Mozilla Firefox browser fixes a flaw that made users vulnerable to on-line fraud. The flaw allowed fraudsters to set up fake websites with names indistinguishable from legitimate companies.

It worked because, to a Firefox user, a Web address with one Cyrillic letter in place of the Latin-script letters used in English could look indistinguishable from an address written completely in Latin script. For instance, a Cyrillic "a" looks just like the Latin "a," but if used in a Web address, it will send the surfer to a different site.

Firefox 1.0.1, released last week, shows Web addresses with foreign scripts in code, preceded by the letters "xn." So "paypal.com" with a Cyrillic "a" becomes "xn — pypal-4ve.com."

This means that perfectly legitimate websites with names in, say, Latvian, will display with the "xn" prefix.

The Mozilla Foundation, which distributes the browser, said the change is temporary, but a long-term solution requires industry cooperation.

The latest "beta" version of the Opera browser, also released last week, makes a similar change. It displays Web addresses in the original script only if they are registered in countries that Opera considers to have proper controls against scam addresses.

Web addresses in foreign scripts do not work in Microsoft Corp.'s Internet Explorer without installing a special plug-in.

[url=\"http://www.globetechnology.com/servlet/story/RTGAM.20050303.gtfirefoxmar2/BNStory/Technology/\"]Globe Technology[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Post Reply

Return to “Security”