OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [suse-security] Spoofing of url-adreslocator

From: Joe Morris (NTM) (Joe_Morrisntm.org)
Date: Tue Feb 08 2005 - 07:37:59 CST


edwin wrote:
>On Mon, 07 Feb 2005 20:55:16 -0600, Joe Morris (NTM) wrote
>
>>Kastus wrote:
>>
>>>On Mon, Feb 07, 2005 at 04:00:42PM -0600, Joe Morris (NTM) wrote:
>>>
>>>
>>>>Just for reference, Mozilla 1.7.5 x86_64 [Mozilla/5.0 (X11; U; Linux
>>>>x86_64; en-US; rv:1.7.5) Gecko/20041220] did not pop up a window (error
>>>>message about not finding www.paypal.com was what happened), so I guess
>>>>it is NOT vulnerable.
>>>>
>
>Maybe this is not what your guys currently discuss but I just got an email
>said that there is a bug in Firefox, Mozilla, Konqueror and Opera about
>address spoofing.
>
>Please check the link
>
>http://secunia.com/multiple_browsers_idn_spoofing_test
This is the test I checked, and if their explanation of the test is
correct, my mozilla (see above), whether because of version or arch,
does not seem to be vulnerable.
--
Joe Morris
New Tribes Mission
Email Address: Joe_Morrisntm.org
Registered Linux user 231871

--
Check the headers for your unsubscription address
For additional commands, e-mail: suse-security-helpsuse.com
Security-related bug reports go to securitysuse.de, not here