• Welcome to Overclockers Forums! Join us to reply in threads, receive reduced ads, and to customize your site experience!

WARNING: non-IE browser problem Mozilla/Firefox users beware

Overclockers is supported by our readers. When you click a link to make a purchase, we may earn a commission. Learn More.

eobard

Give me a break Senior
Joined
Jul 12, 2001
Believe it or not there is an exploitable issue that involves everything but Internet Exploder. Linky.
 
Didn't work for me but I'm in the middle of downloading iso's for Fedora so I can't shutdown and restart until that's done. I may find It works for me once I do that.
 
damn this is anoying...i dont want to do work arounds...wish they would come out w/ patches quick...are there ANY patches for Firefox 1.0? i never DLed ne
 
Ad Rock said:
And now it is making you double post :p.

:)

How many such entries did you guys disable? I had only 2 to comment out.
I used the basic search tool to find any mention of the word idn.

Edit**

It worked!!


I think you need to restart your computer for it to work. Another option would be to reset your internet connection. Seems logical because we are dealing with certain network parameters here, right?

Thanks a lot eoboard!
 
This ins't exactly a security hole. It just allows non-english characters to be in a domain name. The following 3 domain names are really to 3 whole different sites. One of them uses the normal english characters and another one uses the english characters p-a-y-p (and then the Russian Cyrillic letter a which looks indentical to the english character) then an english l. and the third uses the other p-(russian character a)-y-p-a-l.com

(copy and paste these into your address bar)

paypal.com
paypаl.com
pаypal.com
There are other letters that look identical to english letters like o for example:

оcforums.com
yahоо.com

(copy and paste those into your address bar)
look here for more info:
http://webdesign.about.com/od/charactersets/l/blhtmlcodes_ru.htm

IE just doesn't support using IDNs (http://www.ietf.org/html.charters/idn-charter.html) so thats why it isn't affected.

Paypal always says to open a new browser window and type in https://paypal.com and that advice still prevents anything like this from happening.

-Andy
 
I know it's not technically a security flaw in the browser but it could have malicious effects nevertheless so it was worth spreading the news. Closing out Firefox and relaunching after commenting out the two lines worked for me.
 
Back