Browser Bugs Spare Internet Explorer for a Change
Reports surface on several browser bugs. Some affect Firefox only, while another allows address spoofing in every browser except IE.
A vulnerability that allows the URL in the browser address bar to be spoofed appears to affect all Web browsers apart from Internet Explorer. The advisory announcing the vulnerability, which could facilitate phishing and other spoofing attacks, is related to IDN (International Domain Name) support in these browsers. IDN allows for non-English lettering in domain names. It also allows for English lettering using non-English (unicode) character sets. Thus, in the proof-of-concept provided, when linked to "http://www.pаypal.com/" the browsers display "http://www.paypal.com/". But the browsers handle it as "http://www.xnpypal-4ve.com."The advisory lists as vulnerable the following browsers:
- Most Mozilla-based browsers (Firefox 1.0, Camino .8.5, Mozilla 1.6, etc.)
- Safari 1.2.5
- Opera 7.54
- OmniWeb 5
Click here to read about high-risk flaws flagged in Internet Explorer and Mozilla.
Fireflashing allows the contents of the about:config window, which displays Firefox configuration parameters, in a separate window or hidden frame. The user must double-click on a particular area of the display, for which they can be induced by a game or some other prompt, at which point parameters controlling the display of about:config may be changed, as long as the number of parameters is not changed.
Check out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog. 








