<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Oops! This Firefox security exploit is a doozy</title>
	<atom:link href="http://www.edbott.com/weblog/?feed=rss2&#038;p=449" rel="self" type="application/rss+xml" />
	<link>http://www.edbott.com/weblog/?p=449</link>
	<description>Helping PC users make sense of Microsoft software since 1991</description>
	<lastBuildDate>Fri, 20 Nov 2009 18:54:09 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Joe. N.</title>
		<link>http://www.edbott.com/weblog/?p=449&#038;cpage=1#comment-12805</link>
		<dc:creator>Joe. N.</dc:creator>
		<pubDate>Wed, 03 May 2006 09:00:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.edbott.com/wordpress/?p=449#comment-12805</guid>
		<description>Firefox has a new version available for download. According to &lt;a href=&quot;http://www.listerit.com/faqs/blog/firefox-faqs/firefox-users-should-upgrade-to-version-1.5.0.3.html&quot;&gt;this site&lt;/a&gt;, Firefox users should upgrade to version 1.5.0.3

A recent &lt;a href=&quot;http://www.mozilla.org/security/announce/2006/mfsa2006-30.html&quot;&gt;Mozilla Security Bulletin&lt;/a&gt; explains that a possible exploit exists in Firefox version 1.5.0.2 that can cause browser crashes and run malicious code.

To obtain the latest version of Firefox visit:
http://www.mozilla.com/firefox/

&lt;em&gt;[Edited to make links clickable - EB]&lt;/em&gt;</description>
		<content:encoded><![CDATA[<p>Firefox has a new version available for download. According to <a href="http://www.listerit.com/faqs/blog/firefox-faqs/firefox-users-should-upgrade-to-version-1.5.0.3.html">this site</a>, Firefox users should upgrade to version 1.5.0.3</p>
<p>A recent <a href="http://www.mozilla.org/security/announce/2006/mfsa2006-30.html">Mozilla Security Bulletin</a> explains that a possible exploit exists in Firefox version 1.5.0.2 that can cause browser crashes and run malicious code.</p>
<p>To obtain the latest version of Firefox visit:<br />
<a href="http://www.mozilla.com/firefox/" rel="nofollow">http://www.mozilla.com/firefox/</a></p>
<p><em>[Edited to make links clickable - EB]</em></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://www.edbott.com/weblog/?p=449&#038;cpage=1#comment-835</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Wed, 31 Dec 1969 17:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.edbott.com/wordpress/?p=449#comment-835</guid>
		<description>Did I miss something?  When did Safari and Opera get to be Mozilla-based?!  

Last I checked, Safari was KHTML-based (like Konqueror) and Opera was, well Opera-based.</description>
		<content:encoded><![CDATA[<p>Did I miss something?  When did Safari and Opera get to be Mozilla-based?!  </p>
<p>Last I checked, Safari was KHTML-based (like Konqueror) and Opera was, well Opera-based.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://www.edbott.com/weblog/?p=449&#038;cpage=1#comment-836</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Wed, 31 Dec 1969 17:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.edbott.com/wordpress/?p=449#comment-836</guid>
		<description></description>
		<content:encoded><![CDATA[<p>&#8220;you’re vulnerable if you use most Mozilla-based browsers, including Firefox 1.0, or Safari 1.2.5 or Opera 7.54&#8243;</p>
<p>Or perhaps I just mis-parsed that sentence.  It IS a bit ambiguous, now that I look closer.</p>
<p>Perhaps something like this would work better:<br />
&#8220;most Mozilla-based browsers (including Firefox), as well as Safari and Opera&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ed Bott</title>
		<link>http://www.edbott.com/weblog/?p=449&#038;cpage=1#comment-837</link>
		<dc:creator>Ed Bott</dc:creator>
		<pubDate>Wed, 31 Dec 1969 17:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.edbott.com/wordpress/?p=449#comment-837</guid>
		<description>I did not say that Safari or Opera are Mozilla based. The original item read:

&quot;Mozilla-based browsers, including Firefox 1.0, or Safari 1.2.5 or Opera 7.54.&quot;

The list of Mozilla-based browsers includes a number of products, but the best known one is Firefox. This vulnerability affects ALL Mozilla-based browsers AND Safari AND Opera.

Sorry you were confused, and thanks for pointing out the possible ambiguity. I&#039;ve edited the sentence to help other readers avoid making the same mistake.</description>
		<content:encoded><![CDATA[<p>I did not say that Safari or Opera are Mozilla based. The original item read:</p>
<p>&#8220;Mozilla-based browsers, including Firefox 1.0, or Safari 1.2.5 or Opera 7.54.&#8221;</p>
<p>The list of Mozilla-based browsers includes a number of products, but the best known one is Firefox. This vulnerability affects ALL Mozilla-based browsers AND Safari AND Opera.</p>
<p>Sorry you were confused, and thanks for pointing out the possible ambiguity. I&#8217;ve edited the sentence to help other readers avoid making the same mistake.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wes</title>
		<link>http://www.edbott.com/weblog/?p=449&#038;cpage=1#comment-838</link>
		<dc:creator>Wes</dc:creator>
		<pubDate>Wed, 31 Dec 1969 17:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.edbott.com/wordpress/?p=449#comment-838</guid>
		<description>Looking at the responses, it makes me not want to use Opera:
&lt;a href=&quot;http://www.shmoo.com/idn/homograph.txt&quot; rel=&quot;nofollow&quot;&gt;http://www.shmoo.com/idn/homograph.txt&lt;/a&gt;
Vendor Response:
Verisign: No response yet.
Apple:  No response yet.
Opera:  They believe they have correctly implemented IDN, and will not be 
making any changes.
Mozilla:  Working on finding a good long-term solution; provided clear 
workaround for disabling IDN. (That workaround for the technically minded is at the URL above)</description>
		<content:encoded><![CDATA[<p>Looking at the responses, it makes me not want to use Opera:<br />
<a href="http://www.shmoo.com/idn/homograph.txt" rel="nofollow">http://www.shmoo.com/idn/homograph.txt</a><br />
Vendor Response:<br />
Verisign: No response yet.<br />
Apple:  No response yet.<br />
Opera:  They believe they have correctly implemented IDN, and will not be<br />
making any changes.<br />
Mozilla:  Working on finding a good long-term solution; provided clear<br />
workaround for disabling IDN. (That workaround for the technically minded is at the URL above)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jared</title>
		<link>http://www.edbott.com/weblog/?p=449&#038;cpage=1#comment-839</link>
		<dc:creator>Jared</dc:creator>
		<pubDate>Wed, 31 Dec 1969 17:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.edbott.com/wordpress/?p=449#comment-839</guid>
		<description>So, where&#039;s the media coverage on this security vulnerability?  Interesting that anytime IE has a major problem the media has to give it full attention and drag MS down for it.</description>
		<content:encoded><![CDATA[<p>So, where&#8217;s the media coverage on this security vulnerability?  Interesting that anytime IE has a major problem the media has to give it full attention and drag MS down for it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wes</title>
		<link>http://www.edbott.com/weblog/?p=449&#038;cpage=1#comment-840</link>
		<dc:creator>Wes</dc:creator>
		<pubDate>Wed, 31 Dec 1969 17:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.edbott.com/wordpress/?p=449#comment-840</guid>
		<description></description>
		<content:encoded><![CDATA[<p>Where&#8217;s the coverage? <a href="http://news.com.com/Phishing+flaw+a+danger+to+alternative+browsers/2100-1002_3-5566517.html?tag=nefd.top" rel="nofollow">Right here</a></p>
<p>As described in the article, it seems to be more of a security flaw in the structure of the new international domain name system itself.</p>
<p>Quote:The advisory demonstrates the attack using the domain for PayPal, but using an alternate Unicode character for the first &#8220;a.&#8221; That gives an address that looks like &#8220;http://www.pàypal.com,&#8221; but with a smaller &#8220;a.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Juha-Matti</title>
		<link>http://www.edbott.com/weblog/?p=449&#038;cpage=1#comment-841</link>
		<dc:creator>Juha-Matti</dc:creator>
		<pubDate>Wed, 31 Dec 1969 17:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.edbott.com/wordpress/?p=449#comment-841</guid>
		<description>And this was published very soon after security advisories were available from Secunia, X-Force, K-OTiK Security etc. yesterday:

&lt;a href=&quot;http://www.theregister.co.uk/2005/02/07/browsers_idn_spoofing/&quot; rel=&quot;nofollow&quot;&gt;http://www.theregister.co.uk/2005/02/07/browsers_idn_spoofing/&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>And this was published very soon after security advisories were available from Secunia, X-Force, K-OTiK Security etc. yesterday:</p>
<p><a href="http://www.theregister.co.uk/2005/02/07/browsers_idn_spoofing/" rel="nofollow">http://www.theregister.co.uk/2005/02/07/browsers_idn_spoofing/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wes</title>
		<link>http://www.edbott.com/weblog/?p=449&#038;cpage=1#comment-842</link>
		<dc:creator>Wes</dc:creator>
		<pubDate>Wed, 31 Dec 1969 17:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.edbott.com/wordpress/?p=449#comment-842</guid>
		<description>I&#039;d still like to note that the flaw is less with the browser than with the domain system. The only reason IE is unaffected is because it doesn&#039;t understand internationalized domains. This is like someone registering the name paypal.com (but with one or both a&#039;s having an umulat on top) and calling it a browser security exploit.

I think the fix in this case is obvious... Paypal goes to ICANN and ask that the domains with the look-alike letters be taken down.</description>
		<content:encoded><![CDATA[<p>I&#8217;d still like to note that the flaw is less with the browser than with the domain system. The only reason IE is unaffected is because it doesn&#8217;t understand internationalized domains. This is like someone registering the name paypal.com (but with one or both a&#8217;s having an umulat on top) and calling it a browser security exploit.</p>
<p>I think the fix in this case is obvious&#8230; Paypal goes to ICANN and ask that the domains with the look-alike letters be taken down.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ed Bott</title>
		<link>http://www.edbott.com/weblog/?p=449&#038;cpage=1#comment-843</link>
		<dc:creator>Ed Bott</dc:creator>
		<pubDate>Wed, 31 Dec 1969 17:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.edbott.com/wordpress/?p=449#comment-843</guid>
		<description>I&#039;m really not sure I understand the distinction, Wes. The IDN is designed to provide a way for browsers to *recognize* names that contain characters from alternate character sets. If the domain name contains an accented letter A from another character set, it shouldn&#039;t be recognized as a regular unaccented A from the Latin character set. That&#039;s the bug in Firefox, and the fact that they&#039;ve already checked in a fix for it suggests that they agree the problem is theirs.

As for ICANN... Phishers are hit-and-run artists. They do their work with domains they know are going to expire within 48 hours. PayPal is reporting them to legal authorities and getting the sites taken down as fast as they can. Do you think ICANN would get to them any faster?</description>
		<content:encoded><![CDATA[<p>I&#8217;m really not sure I understand the distinction, Wes. The IDN is designed to provide a way for browsers to *recognize* names that contain characters from alternate character sets. If the domain name contains an accented letter A from another character set, it shouldn&#8217;t be recognized as a regular unaccented A from the Latin character set. That&#8217;s the bug in Firefox, and the fact that they&#8217;ve already checked in a fix for it suggests that they agree the problem is theirs.</p>
<p>As for ICANN&#8230; Phishers are hit-and-run artists. They do their work with domains they know are going to expire within 48 hours. PayPal is reporting them to legal authorities and getting the sites taken down as fast as they can. Do you think ICANN would get to them any faster?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: franCk</title>
		<link>http://www.edbott.com/weblog/?p=449&#038;cpage=1#comment-844</link>
		<dc:creator>franCk</dc:creator>
		<pubDate>Wed, 31 Dec 1969 17:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.edbott.com/wordpress/?p=449#comment-844</guid>
		<description>Well, ICANN allowing the domain registration *is* the problem here - they don&#039;t do their job properly.
Otherwise what is the purpose of domain registration? Why do we need an authority if it&#039;s not to &#039;protect&#039; users? If they don&#039;t do any screening of domain, then we don&#039;t need them at all and they should disappear - at least the situation will be clearer and the ball will be clearly set in the browser hand (and Opera would probably do something about it :-).
Thus, I think this phishing shows that ICANN should die, they are useless.

In the other hand why IE won&#039;t claim loud that they have no problem with it, is just because it will be too easy to remark that the phishing does not work with IE because they don&#039;t support IDN at all... a very bad publicity in the ever growing international world (remember than the English web is now less than half the web:-)</description>
		<content:encoded><![CDATA[<p>Well, ICANN allowing the domain registration *is* the problem here &#8211; they don&#8217;t do their job properly.<br />
Otherwise what is the purpose of domain registration? Why do we need an authority if it&#8217;s not to &#8216;protect&#8217; users? If they don&#8217;t do any screening of domain, then we don&#8217;t need them at all and they should disappear &#8211; at least the situation will be clearer and the ball will be clearly set in the browser hand (and Opera would probably do something about it <img src='http://www.edbott.com/weblog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> .<br />
Thus, I think this phishing shows that ICANN should die, they are useless.</p>
<p>In the other hand why IE won&#8217;t claim loud that they have no problem with it, is just because it will be too easy to remark that the phishing does not work with IE because they don&#8217;t support IDN at all&#8230; a very bad publicity in the ever growing international world (remember than the English web is now less than half the web:-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Guy MS</title>
		<link>http://www.edbott.com/weblog/?p=449&#038;cpage=1#comment-845</link>
		<dc:creator>Guy MS</dc:creator>
		<pubDate>Wed, 31 Dec 1969 17:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.edbott.com/wordpress/?p=449#comment-845</guid>
		<description>Maybe the people at MS have the ability to think ahead and thus have not implemented the IDN for a reason they foresaw.. duh.  Oh yeah- they also have companies running mission critical software, not just geeks in their parents basements (myself included! HAHA).  Anyway- everyone thinks firefox is the greatest thing now- funny no one mentions Netscape.. 
</description>
		<content:encoded><![CDATA[<p>Maybe the people at MS have the ability to think ahead and thus have not implemented the IDN for a reason they foresaw.. duh.  Oh yeah- they also have companies running mission critical software, not just geeks in their parents basements (myself included! HAHA).  Anyway- everyone thinks firefox is the greatest thing now- funny no one mentions Netscape..</p>
]]></content:encoded>
	</item>
</channel>
</rss>
