(no subject)
Feb. 15th, 2005 09:42 am[edit] I'm just posting links and a suggestion I received. Please verify the info yourself before installing or changing anything - I refuse to be responsible for any computer deaths!
To be honest I haven't had time to read this in detail yet, so please check the source of info etc yourselves.
News article on new phishing exploits that affects FireFox browsers
Original paper from the conference that exposed this vulnerability
Apparently there is a work-around. Again I haven't checked any of this info. It was sent out by the IT director of my sis's workplace and she forwarded it to me:
+++
There is a workaround, and I urge you to perform this tweak in order to make keep FireFox a safer and just more generally righteous web browser:
type
about:config
into the FireFox address bar. You'll be presented with a page of configuration options. Scroll down to
network.enableIDN
Double click this option to switch it's value from true to false. Having a setting of false will prevent you from being a victim of one of the most dangerous phishing attacks that I've ever seen. I don't normally send out advisories like this, but this one is such a doozy....
+++
To be honest I haven't had time to read this in detail yet, so please check the source of info etc yourselves.
News article on new phishing exploits that affects FireFox browsers
Original paper from the conference that exposed this vulnerability
Apparently there is a work-around. Again I haven't checked any of this info. It was sent out by the IT director of my sis's workplace and she forwarded it to me:
+++
There is a workaround, and I urge you to perform this tweak in order to make keep FireFox a safer and just more generally righteous web browser:
type
about:config
into the FireFox address bar. You'll be presented with a page of configuration options. Scroll down to
network.enableIDN
Double click this option to switch it's value from true to false. Having a setting of false will prevent you from being a victim of one of the most dangerous phishing attacks that I've ever seen. I don't normally send out advisories like this, but this one is such a doozy....
+++