Re: [SLUG] IE _not_ included in new URL spoof exploit

From: Mark Polhamus (meplists@earthlink.net)
Date: Tue Feb 08 2005 - 09:13:49 EST


Christopher Hotchkiss wrote:
> On Mon, 07 Feb 2005 21:58:27 -0500, 404 <matthew@textbox.net> wrote:
>
>>On Mon, 2005-02-07 at 21:41, perthie wrote:
>>
>>>I would expect to see "www.p&#1072;ypal.com/" In the status bar, but I
>>>see "www.paypal.com" with either setting in firefox. Is this not what I
>>>should be looking at? By the way, I get the same results in IE.
>
> Be careful some user have reported that the setting invisably reverts
> itself when you restart the browser. It will still say false but the
> exploit will still work.

That's right. Lots more information here:
http://www.dslreports.com/forum/remark,12603456~mode=flat, and
http://forums.mozillazine.org/viewtopic.php?t=215221 including a different
workaround.

-- Mark Polhamus

-----------------------------------------------------------------------
This list is provided as an unmoderated internet service by Networked
Knowledge Systems (NKS). Views and opinions expressed in messages
posted are those of the author and do not necessarily reflect the
official policy or position of NKS or any of its employees.



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 18:46:41 EDT