cancel
Showing results forย 
Search instead forย 
Did you mean:ย 

Serious Flaw in Firefox and Chrome Browsers!

1492
Moderator
Moderator
I thought I'd pass along this potential vulnerability in Firefox and Chrome browsers which is receiving increased attention in online security communities. It involves Unicode phishing vulnerability, where clicking a link to what appears a legit URL, can actually be a fake website.

In fact, if you are using Firefox or Chrome browser right now? Try clicking this link:



Look at your browser's URL address bar? Does it say https://apple.com. Obviously, not an Apple website? Notice how the browser also appears to indicate a valid site certificate (https://)? Further demonstrating how hackers could potentially clone Apple's site to make it look legit, leaving a door open to steal personal account info?

Now try clicking the link using MS Internet Explorer (IE) browser? Notice that the URL address bar correctly indicates the site address as https://www.xn--80ak6aa92e.com/? IE is not affected by the Unicode vulnerability?

Until patches are available for both Firefox and Chrome browsers, it is advisable not to click links to websites in emails, or other unfamiliar sources. Instead type the URL website link directly into the browser address bar. Or use IE browser in the intern.

For Firefox users who feel comfortable in making browser config changes, you can adjust the following browser setting to temporarily mitigate the Unicode vulnerability:

  1. Type or copy and paste about:config in the URL address bar.
  2. Click the "I'll be careful, I promise!" button.
  3. Type or copy and paste network.IDN_show_punycode in Search bar.
  4. Double mouse click the line network.IDN_show_punycode until Value column changes to true.
  5. Close the browser tab.

Now try clicking the fake URL link above once again as a test? Should now read https://www.xn--80ak6aa92e.com/?



For further reference, see:


This Phishing Attack is Almost Impossible to Detect...


Phishing with Unicode Domains
59 REPLIES 59

MrWizard
Moderator
Moderator
thanks
just fixed FF
I can explain it to you.
But I Can Not understand it for you !

....

Connected using T-Mobile Home internet and Visible Phone service
1997 F53 Bounder 36s

bob213
Explorer
Explorer
Chrome and Opera users can use the PunyCodeAlert extension.
You can avoid reality, but you cannot avoid the consequences of avoiding reality โ€“ Ayn Rand

joebedford
Nomad II
Nomad II
Hmmm. Latest download of Opera doesn't correct the problem.

outdoorlovers
Explorer
Explorer
I have Chrome and it wouldn't take me to the site. I received an immediate alert.
2012 Dodge Ram 2500, Cummins turbo diesel, 6 speed, 4X4, tow package
2014 Jayco FW Eagle HT 26.5 RLS
Yamaha EF2400iS gen

loggenrock
Explorer
Explorer
You guys rock! Problem identified - Chrome updated - all within 5 minutes! Thanks to all! ST
Two and a hound in a 2015 Coachmen Prism "B+"...pushed by '09 Suby Forester
First 50 done, working on the second pass! Nunavut - we'll see...!
2005-2015 Roadtrek 190P
1993-2005 Northstar Soft-Side TC
1989-1993 Backpacks & Tents!
1967-1977 Family TT's

Fizz
Explorer
Explorer
Thanks for the heads up, all is good now... till the next crisis.

1492
Moderator
Moderator
overbrook wrote:
Google has just released an update to Chrome that fixes the problem.


Just upgraded to the latest release of Chrome in Windows 7, and confirmed it does fix the Unicode domain vulnerability.



1492
Moderator
Moderator
downtheroad wrote:
Firefox 53.0 was just released....

Just upgraded to Firefox 53, but the Unicode flaw still exists. Need to also change the config file manually in this version.

mike-uswest
Explorer
Explorer
Done. Thanks.

Mike
2019 Ram 2500 TCD, 4X4,
Arctic Fox 25Y 30'

overbrook
Explorer III
Explorer III
Google has just released an update to Chrome that fixes the problem. To get the update in Chrome, click the 3 vertical buttons on the far right top menu and choose 'help', and then click 'about Google Chrome'.

This will start the update which takes less than a minute.

After the update, if you visit the demo link in the hacker article linked above, you'll see it no longer shows the phishing url (apple.com).

Bill
Coachhouse Platinum 232 XL

downtheroad
Explorer
Explorer
Firefox 53.0 was just released....
"If we couldn't laugh we would all go insane."

Arctic Fox 25Y
GMC Duramax
Blue Ox SwayPro

azrving
Explorer
Explorer
Geez even I could fix it. You are bad to the bone 1492. Thank you

Chris_Bryant
Explorer II
Explorer II
1492 wrote:
Just want to re-iterate that this is a browser specific vulnerability, and not an OS issue. So far tested and found the flaw on these current versions of Firefox and Chrome:

    Windows 7 Enterprise: Firefox-Yes Chrome-Yes
    MAC OS X Sierra: Firefox-Yes Chrome-Yes
    Red Hat Linux (RHEL): Firefox-Yes Chrome-No, patched.


Interesting- the Chrome patch must be from RedHat, not Google. Both my ChromeOS and Debian Linux installs of Chrome are still vulnerable, though I understand that the Beta release is patched.
-- Chris Bryant

joebedford
Nomad II
Nomad II
Opera falls for this trick too. I just tried it.

1492
Moderator
Moderator
Just want to re-iterate that this is a browser specific vulnerability, and not an OS issue. So far tested and found the flaw on these current versions of Firefox and Chrome:

    Windows 7 Enterprise: Firefox-Yes Chrome-Yes
    MAC OS X Sierra: Firefox-Yes Chrome-Yes
    Red Hat Linux (RHEL): Firefox-Yes Chrome-No, patched.