Chrome, Firefox, and Opera Vulnerable to Undetectable Phishing Attack

Discussion in 'other security issues & news' started by Mr.X, Apr 17, 2017.

  1. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,813
    Location:
    .
    https://www.bleepingcomputer.com/ne...a-vulnerable-to-undetectable-phishing-attack/
     
  2. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,078
    Location:
    DC Metro Area
  3. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,813
    Location:
    .
    Good news.
     
  4. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,508
    Wow not cool. Glad patches are coming however.
     
  5. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,645
    Location:
    USA
    I knew when ICANN voted to allow this stupidity that it would cause issues. I didn't expect it to take this long to be a thing though.
     
  6. The Red Moon

    The Red Moon Registered Member

    Joined:
    May 17, 2012
    Posts:
    4,101
    Pale moon browser has mitigated this attempt for quite a long time.
     
  7. guest

    guest Guest

    It is affected too. You have to set "network.IDN_show_punycode" to true (false is the default) to mitigate it.
     
  8. The Red Moon

    The Red Moon Registered Member

    Joined:
    May 17, 2012
    Posts:
    4,101
    No.
    palemoon is protected even without toggling the about:config setting.Pale moon refuses to connect to such servers.
     
  9. guest

    guest Guest

  10. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    No problem here with FF v3.6.14

    FF Pass.png
    Funny, my about:config shows false, but it still showed me the true URL

    Thanx to mood for the link
     
  11. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
  12. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    1,762
    Hovering the mouse over the link in Firefox discloses the scam, but if don't check before you click then the change in about:config will help., You still need to notice what is displaying in the address bar though.
     
  13. CHEFKOCH

    CHEFKOCH Registered Member

    Joined:
    Aug 29, 2014
    Posts:
    395
    Location:
    Swiss
    Nope, some cyrillic letters are same like greek. So you not know if it's an a or an a.
     
  14. guest

    guest Guest

    Pale Moon is using a blacklist and if an unicode character looks similar to an ASCII character, the URL will be shown in ASCII characters:
    But if characters are not on the "blacklist", the URL is displayed like in other vulnerable browsers.
    network.IDN_show_punycode should be set to true to mitigate this.
    The user can also check the certificate of https-sites:
    PaleMoon_https_punycode.png
    There will be a change in the next version of Pale Moon:
     
  15. guest

    guest Guest

  16. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,813
    Location:
    .
    Thanks for good news.
     
  17. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Yes exactly, weird that they never spotted this hole.
     
  18. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,813
    Location:
    .
    Indeed, vuln fixed in Chrome v58:

    vuln.png
     
  19. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,508
    Agreed.
     
  20. guest

    guest Guest

    It seems that Mozilla won't fix this issue:
    See Comment 78:
     
  21. clubhouse1

    clubhouse1 Registered Member

    Joined:
    Sep 26, 2013
    Posts:
    1,124
    Location:
    UK
  22. guest

    guest Guest

    The result (screenshot of the matrix) can be seen in the uBlockO-thread:
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.