On CNET: Dell spikes site with Alienware PCs
BNET Business Network:
BNET
TechRepublic
ZDNet

By Steven Musil, News.com
Posted on ZDNet News: Feb 25, 2005 5:00:00 AM

The Mozilla Foundation released on Thursday an update to the Firefox Web browser to fix several vulnerabilities, including one that would allow domain spoofing.

The open-source project released Firefox 1.0.1 to fix, among other bugs, a vulnerability in the Internationalized Domain Names (IDN), a standard for handling special character sets in domain names that lets companies register domain names that appear to be the same in different languages.

The IDN vulnerability allowed an attacker to create a fake Web site on a non-Microsoft browser in order to pull off a phishing scam. A spoofed link would seem to be a legitimate URL in the address bar of affected browsers. But instead of taking the victim to the trusted site, the link would lead to a phony Web site with a domain rendered as the same address under the IDN process.

The updated browser will display the IDN Punycode in the address bar, preventing URL spoofing. Punycode is the encoding of Unicode strings into the limited character set supported by the Domain Name System and IDN.

"Regular security updates are essential for maintaining a safe browsing experience for our users," Chris Hofmann, director of engineering for the Mozilla Foundation, said in a statement.

Phishing attacks, which try to fool consumers into handing over sensitive information by creating legitimate-looking Web sites and e-mail messages, have become a central security concern recently. While vulnerabilities in Microsoft's Internet Explorer have been the focus of much of the concern, other browsers also have had their fair share of flaws.

The update is available for Windows, Mac OS X and Linux at Mozilla.org.

Firefox recently surpassed 25 million downloads, achieving that mark in 100 days. Mozilla, which released the free 1.0 program in November, said an average of 250,000 people download Firefox every day and more than half a million Web sites feature Firefox promotions.

Mozilla, an open-source software foundation formed by Netscape, was spun off from Time Warner in 2003.

  • Talkback
  • Most Recent of 307 Talkback(s)
YES
HA! HA! YOUR POST GOT DELETED.
I am going to say this just once. I don't have time to run everything through a spell checker like you. I am a busy man. So therefore there are bound to be some mista... (Read the rest)
Posted by: IceTheNet@... Posted on: 03/24/05 You are currently: Logged In | Log out
Oops! ISD_z   | 02/24/05
I'm not worried mad.mutt   | 02/24/05
How True djc1309@...   | 02/26/05
Re: Oops! DrDavis   | 02/25/05
bandwagon Anti_Zealot   | 02/25/05
You and others like you... vferrara   | 02/25/05
Not sure where you get your info voska   | 02/25/05
Hear hear dch48   | 02/25/05
How can Linux User 147560   | 02/26/05
Because... Spoon Jabber   | 02/27/05
points... maxo_z   | 02/25/05
Different strokes for different folks FilledOut   | 02/25/05
I got your band, right here. Firefox vs. IE el1jones   | 02/25/05
95%/80% discrepancy. Sotek   | 02/25/05
RE: 95%/80% discrepancy douglen@...   | 03/03/05
Of...... todbran@...   | 02/25/05
Facts don't matter neverhome   | 02/25/05
NBM bandwagon Anti_Zealot   | 02/25/05
HA HA HA HA... slingzenarrowzuvowtrayjissforchin   | 02/25/05
Forget it Immanuel Tranz-Mischen   | 02/25/05
OOPS, IE too ivanii   | 02/25/05
Do research.... hawkeyeaz1   | 02/25/05
Sorry, we were downloading the update ... now what were you saying? Hugh Jass   | 02/25/05
MS - baad rrfe@...   | 02/27/05
I noticed that the "FIX-TIME" was miniscule compared to M$ (NT) Update victim   | 02/28/05
Wassup? I thought Firefox has no security issues? Prognosticator   | 02/25/05
Bummer... nucrash   | 02/25/05
MS abandoned browsers RoberNet   | 03/03/05
Who said that? Michael Kelly   | 02/25/05
ActiveX dloyd   | 02/26/05
There is a difference maddoghall   | 02/26/05
Funny you mention this AmusedAtItAll   | 02/26/05
That's your problem Martin Marvinski   | 02/25/05
Firefox is a niche product for people that jogiba@...   | 02/25/05
Who are you talking to? hawkeyeaz1   | 02/25/05
IE was good in it's day but it's old now voska   | 02/25/05
A real computer Guru are you! AmusedAtItAll   | 02/26/05
you have noticed turtleboy211   | 02/28/05
No, just a lot less, and they get fixed right away, no coverup DonnieBoy   | 02/25/05
It isn't an issue with Firefox... Oscar_Goldman   | 02/25/05
Well, it still needs to be fixed. I am glad they just shut up and fix it. DonnieBoy   | 02/25/05
RE: cubmiester   | 02/25/05
Only a few.....so far cicuta   | 02/25/05
Excellent Point TrueSpeak   | 02/25/05
I'd say... Spoon Jabber   | 02/25/05
My point exactly TrueSpeak   | 02/25/05
Starting from Scratch? mds_z   | 02/25/05
I think the post was "FF that started from scratch" (NT) Spoon Jabber   | 02/25/05
All words in caps would be yelling Spoon Jabber   | 02/25/05
Uh, what about Mozilla and Netscape.... el1jones   | 02/25/05
What exactly is your point? AmusedAtItAll   | 02/26/05
By this logic then - klmmicro   | 02/25/05
Check the numbers hawkeyeaz1   | 02/25/05
Nice Theory James Wojciehowski   | 02/25/05
Why don't you MSDrones stop beating that horse? AmusedAtItAll   | 02/26/05
You... todbran@...   | 02/25/05
What? htotten   | 02/25/05
Uhm, no no no no no. hawkeyeaz1   | 02/25/05
Yes. And they are fixed more promptely than IE. No spyware ivanii   | 02/25/05
You thought??? Immanuel Tranz-Mischen   | 02/25/05
Sheesh. dalecosp   | 02/26/05
Reply to da Dreamer . . . Trav_z   | 03/02/05
The only thing I don't like... Real World   | 02/25/05
It's a small download anyway Michael Kelly   | 02/25/05
I agree, there must be a way to easily slipstream Jeff Spicoli   | 02/25/05
Good of 'em Loverock Davidson   | 02/25/05
You........use FF? (NT) Spoon Jabber   | 02/25/05
Yes Loverock Davidson   | 02/25/05
My apologies... Spoon Jabber   | 02/25/05
Its all good Loverock Davidson   | 02/25/05
You mean "F"riend? : ) Spoon Jabber   | 02/25/05
gag ... hack ... cough ... sputter Judas I.   | 02/25/05
obutter Loverock Davidson   | 02/25/05
Extra work not always needed osreinstall   | 02/25/05
Loverock Judas I.   | 02/26/05
Don't be taken in, man AmusedAtItAll   | 02/26/05
Easy there fella Loverock Davidson   | 02/27/05
Impossible EJHonda   | 02/25/05
You're not Jeff Spicoli   | 02/25/05
Vulnerability was fixed before Exploited timoute   | 02/25/05
Wrong EJHonda   | 02/25/05
Really? Jeff Spicoli   | 02/25/05
Here U go... EJHonda   | 02/25/05
But.. Jeff Spicoli   | 02/25/05
I almost got nailed on Mozilla 1.73 osreinstall   | 02/25/05
At least it asked you voska   | 02/25/05
RE: I almost got nailed on Mozilla 1.73 AmusedAtItAll   | 02/26/05
yeah right dch48   | 02/25/05
Its OK AmusedAtItAll   | 02/26/05
Window Injection Vulnerability kingoferth   | 02/25/05
Do we KNOW that for certain? Michael Kelly   | 02/25/05
Same Here neverhome   | 02/25/05
Not enabled yet Spoon Jabber   | 02/25/05
Enabled, but FF1.0.1 not on update server yet ivanii   | 02/25/05
why switch wessonjoe   | 02/28/05
Lets see, Microsoft would say this is a problem with domain names. DonnieBoy   | 02/25/05
Of course they do neverhome   | 02/25/05
Why do you say that? hawkeyeaz1   | 02/25/05
YSR bumberfsck   | 02/25/05
Its been known... hawkeyeaz1   | 02/25/05
Does that mean.. AmusedAtItAll   | 02/26/05
OK now for my weekly Firefox gripes Michael Kelly   | 02/25/05
Funny you mention it IT_User   | 02/25/05
One answer to one of your gripes Loverock Davidson   | 02/25/05
Thanks Michael Kelly   | 02/25/05
Tools > Options > Advanced > Check Now itanalyst   | 02/25/05
But,... Spoon Jabber   | 02/25/05
3 things Michael Kelly   | 02/25/05
Backlash rapson   | 02/25/05
I'll bite Squawkbox   | 02/25/05
You click "Check Now" and it finds no update Michael Kelly   | 02/25/05
Thanks Mike Squawkbox   | 02/25/05
I want that too Michael Kelly   | 02/25/05
Auto update is on by default... widge_z   | 02/25/05
Ohhh now I get it Squawkbox   | 02/25/05
Not a prob... widge_z   | 02/25/05
My update button worked todbran@...   | 02/25/05
Only for extensions and themes Spoon Jabber   | 02/25/05
Yes, I got extension and theme updates too (nt) Michael Kelly   | 02/25/05
One thing.. Jeff Spicoli   | 02/25/05
I'm not seeing that :( Michael Kelly   | 02/25/05
I'm using.. Jeff Spicoli   | 02/25/05
Da whole thang neverhome   | 02/25/05
I've glanced at the talkbacks and here is what Laff   | 02/25/05
Agreed cubmiester   | 02/25/05
Definitely percent of successes v attempts Spoon Jabber   | 02/25/05
Awww c'mon Jim you are missing the point here Squawkbox   | 02/25/05
Are you saying Spoon Jabber   | 02/25/05
Ummmm yep Squawkbox   | 02/25/05
Well.... AmraLeo   | 02/25/05
Ohboy a new toy. I love new toys. Squawkbox   | 02/25/05
True, but who determines the "success rate"? cicuta   | 02/25/05
Your conclusion is ridiculous! ShadeTree   | 02/25/05
So what's your excuse for IIS then? Jeff Spicoli   | 02/25/05
It is also from Microsoft ... ShadeTree   | 02/25/05
You just killed your own "argument" Jeff Spicoli   | 02/25/05
Actually if my conclusions are off so are yours Laff   | 02/25/05
I did not state a preference for either ... ShadeTree   | 02/25/05
I have only logic...A browser that was designed with Laff   | 02/25/05
Of course you're right IT_User   | 02/25/05
LOL, that's funny voska   | 02/25/05
Do NOT underestimate the value of CORN NUTS! Laff   | 02/25/05
Very quickly fixed! Spoon Jabber   | 02/25/05
Tools -> options -> advanced (in the software update section) widge_z   | 02/25/05
Doesn't work Spoon Jabber   | 02/25/05
Shooting self in foot? mikew_z   | 02/25/05
while the register shoots itself in the head IceTheNet@...   | 02/25/05
security and browsers jimmurray1946   | 02/25/05
Firefox fixes brike@...   | 02/25/05
fud IceTheNet@...   | 02/25/05
Neither IE or Firefox-----OPERA!!! DumbUser   | 02/25/05
pssssst... todbran@...   | 02/25/05
Bingo, FilledOut   | 02/25/05
more pssssst! osreinstall   | 02/25/05
even more pssssst IceTheNet@...   | 02/25/05
Neither... TallMonke   | 02/25/05
I may have to reconsider my stance on a Laff   | 02/25/05
Coke Spoon.. Jeff Spicoli   | 02/25/05
Tried a Coke spoon once...can't say I see the Laff   | 02/25/05
Also don't try... neverhome   | 02/25/05
There is hope in dope Jeff Spicoli   | 02/25/05
Well, I prefer... Spoon Jabber   | 02/25/05
deliberate word switching Jeff Spicoli   | 02/25/05
Coke spoons AmraLeo   | 02/25/05
Surely it was an accident! (NT) Spoon Jabber   | 02/25/05
The Emperor Wears No Clothes Jazhawk   | 02/25/05
You do realize the IE has had X amount of hacks Laff   | 02/25/05
Proof Firefox is a SECURITY risk. Jazhawk   | 02/25/05
It is true that one time will tell this tale still and Laff   | 02/25/05
I think not Squawkbox   | 02/25/05
There you go using those PESKY FACTS again. Laff   | 02/25/05
Re: You do realize the IE has had X amount of hacks bumberfsck   | 02/25/05
While I will grand you the length a browser has Laff   | 02/25/05
but still you miss the point IceTheNet@...   | 02/25/05
HOW DO I GET THE UPDATE??? neverhome   | 02/25/05
http://www.mozilla.org/ Squawkbox   | 02/25/05
The whole thing? neverhome   | 02/25/05
Yep as the old Alka Seltzer commercial said Squawkbox   | 02/25/05
or http://www.spreadfirefox.com/ Squawkbox   | 02/25/05
just download Firefox 1.0.1 wexwimpy@...   | 02/25/05
Um, download it ? BitTwiddler   | 02/28/05
Jeff - Another Video For You itanalyst   | 02/25/05
I can't believe they deleted the other post Jeff Spicoli   | 02/25/05
Dang Jefreeee you are becoming a poster child of deleted posts Squawkbox   | 02/25/05
You own a Pharmacutical? :) Laff   | 02/26/05
Bwahahahahaha!! Jeff Spicoli   | 02/26/05
Nuttin better than a buzz w/ buds and an updated FIREFOX BROWSER Squawkbox   | 02/26/05
Last week they left up a neurotic rant equating Microsoft with nazism Hugh Jass   | 02/25/05
IDN spoofing due to ICANN, not Firefox ivanii   | 02/25/05
Actual Usage vs. Downloads neverhome   | 02/25/05
FF visitors to your website coffeegurrl   | 02/25/05
Reality Please neverhome   | 02/25/05
Stop scaring off... MepisLINUXuser   | 02/25/05
Who goes to your site? Anton Philidor   | 02/25/05
Good Point neverhome   | 02/25/05
Who goes to your site? Jay Cash   | 02/25/05
Don't forget... BitTwiddler   | 02/28/05
actual wexwimpy@...   | 02/25/05
Don't Know neverhome   | 02/25/05
Maybe FF users don't... MepisLINUXuser   | 02/25/05
Agree- some misleading information patience@...   | 03/02/05
Firefox has a security hole? CodeBubba   | 02/25/05
Firefox bulletproof wexwimpy@...   | 02/25/05
The delay in updating shows a major problem for FireFox. Anton Philidor   | 02/25/05
Give'em time neverhome   | 02/25/05
I think if they were really worried IceTheNet@...   | 02/25/05
AOL removed its support from Mozilla. Anton Philidor   | 02/25/05
Thank's for the info IceTheNet@...   | 03/24/05
Can a major browser hope for "charity"? Linux_Developer   | 02/25/05