BugTraq
RE: thoughts and a possible solution on homograph attacks Mar 07 2005 08:05PM
Scovetta, Michael V (Michael Scovetta ca com) (2 replies)
Re: houghts and a possible solution on homograph attacks Mar 08 2005 06:50PM
Sven Putteneers (svennieboy linux be) (1 replies)
On Mon, 7 Mar 2005 at 15:05:51 -0500, Scovetta, Michael V(Michael.Scovetta (at) ca (dot) com [email concealed]) wrote:
>
> <plug>
> I've released a "fix" for the IDN vulnerability
> (www.scovettalabs.com/advisory/SCL-2005.002.txt) that basically prevents
> you from going to *any* domain that has a non-[\-A-Z0-9] character in
> it. For me, it's fine, since I'll likely never need to go to an IDN
> domain.
> </plug>

If this patch would be widely used, we'd lose the all the advantages
associated with IDN.
Maybe it's better to attack this problem on the browser side and have a
configuration switch to enable or disable IDN. We could disable it as a
"reasonable default", but those who need it, could enable it.
Upon enabling the option, a warning dialog could pop up that warns the
user about the security problems associated with IDN ("don't enable this
unless you know what you're doing" stuff).

That way the majority of the users would be safe from IDN attacks
(phishing comes to mind) and those who really want IDN would have to
click through a warning dialog telling them why enabling it may not be
such a good idea.

Just my â?¬0.02,
Sven

--
Encrypted mail preferred. As of Jan 27th 2005, all outgoing mail is signed.
GPG keyID: 0x66A13305
GPG key fingerprint: 5B8C 97A2 20C4 E578 CDEB 71C9 23CA 0681 66A1 3305
GPG key URL: http://werner.sytes.net/~svenniboy/gpg_pubkey.asc

[ reply ]
Re: houghts and a possible solution on homograph attacks Mar 09 2005 12:48AM
Nick FitzGerald (nick virus-l demon co uk) (1 replies)
Re: Thoughts and a possible solution on homograph attacks Mar 11 2005 10:42AM
Paul Smith (paullocal pscs co uk) (1 replies)
Re: Thoughts and a possible solution on homograph attacks Mar 15 2005 11:27AM
Riccardo Murri (murri dmmm uniroma1 it) (2 replies)
Re: Thoughts and a possible solution on homograph attacks Mar 16 2005 12:10AM
khockenb (khockenb stevens edu) (1 replies)
Re: Thoughts and a possible solution on homograph attacks Mar 16 2005 10:02AM
Riccardo Murri (riccardo murri ictp it)
Re: Thoughts and a possible solution on homograph attacks Mar 15 2005 09:09PM
Valdis Kletnieks vt edu
Re: thoughts and a possible solution on homograph attacks Mar 08 2005 12:33PM
Mike Nice (niceman att net)


 

Privacy Statement
Copyright 2010, SecurityFocus