<rss version="0.91"><channel>
<title>Oops! This Firefox security exploit is a doozy</title>
<link>http://www.edbott.com/weblog/archives/000449.html</link>
<description>Last month, I predicted that as Firefox became more popular it would face more and more attacks from the Internet&rsquo;s dark side.&nbsp;A security bulletin issued today appears to&nbsp;identify&nbsp;the first&nbsp;widespread security exploit aimed at non-Microsoft browsers. Ironically, you&rsquo;re protected if you use Internet Explorer, but you&rsquo;re vulnerable if you use&nbsp;most Mozilla-based browsers, including Firefox 1.0;&nbsp;this vulnerability&nbsp;also affects&nbsp;Safari 1.2.5&nbsp;(Macintosh) and Opera 7.54, and perhaps other versions of those browsers as well. Here&rsquo;s how it works: You visit an innocent-looking Web page or receive a seemingly authentic e-mail. You click a link that appears to take you to a trusted site (the security advisory uses PayPal&nbsp;as an example)&nbsp;using your default browser, Firefox. The URL in the Address bar says you&rsquo;re at PayPal&rsquo;s site, and the locked padlock icon in the lower right corner indicated that you&rsquo;re on a secure site. The only trouble is, you&rsquo;re not at PayPal&rsquo;s site. You&rsquo;ve just landed at a site owned by someone who wants to steal your information, and even a careful and suspicious visitor can be fooled by this exploit. The exploit happens because of a flaw in the way these browsers handle &ldquo;punycode&rdquo; &ndash; links that use codepages and scripts that are similar to Latin-based characters. And the same technique could be used for any site. A demonstration of the exploit appears here: http://www.shmoo.com/idn/ Don&rsquo;t worry, the demo is harmless. But a scam artist who can cut and paste HTML source code can turn the landing page into an exact duplicate of PayPal&rsquo;s site, or your online banking portal, or a shopping site, or anything they want. This sort of scam will fool a lot of people. The only indication that you&rsquo;re not at the correct site appears if you choose the option to use a secure logon and check the security certificate. Even then,...</description>
<language>en-us</language>
<item>
<title>texas holdem</title>
<link>http://www.texas----holdem.us</link>
<description><![CDATA[ <a href='http://www.on-line--poker.us'>online poker</a> <a href='http://www.texas----holdem.us'>texas holdem</a> <a href='http://www.hold--em.us'>texas hold'em</a> <a href='http://www.hold-em-online.us'>texas hold'em</a>]]></description>
</item>
</channel>
</rss>
