It’s an IDN thing

Ben asks whether the Verisign IE plugin for IDN is vulnerable to the same phishing attack as the browsers that have implemented IDN natively.

I’d have to say, mostly.

Screenshot of IE showing Secunia's IDN Paypal spoof

The addressbar looks fine, a perfect spoof, and on Shmoo’s secure site everything looks fine until you examine the certificate, or for any site look at the page properties, since the plugin doesn’t affect that and you see the punycode “https://www.xn--pypal-4ve.com/.”

Screenshot of IE showing Shmoo's IDN Paypal SSL spoof

I tried to remember the last time I examined the certificate for a site I thought I knew, and couldn’t; probably sometime in the first year that I used the internet. Good enough to phish me.

(The title in the Windows titlebar on the Shmoo site isn’t really a flaw in the spoof: they just didn’t bother with an HTML <title> so IE shows the URI instead.)

2 Comments

Comment by Phil Ringnalda #
2005-02-09 09:37:32

Nice. I thought it was a little odd that Ben has TrackBack enabled on every entry, but I never seem to see any pings, but hey, maybe I just read them too soon after he posts. Should have realized that it’s just like bugmail, where you think you are talking to him without knowing that he’ll never hear a word you say. Ping ’http://weblogs.mozillazine.org/mt/track.cgi/3482’ failed: You are not allowed to send TrackBack pings. Live and learn.

 
Trackback by Will's Blog #
2005-02-09 13:48:59

Major Browser Security Flaw (including IE?)

phil ringnalda dot com: It’s an IDN thing That’s interesting…from what I had heard it was a non-IE bug. But the screenshots seem to prove that it affects IE as well. Local tests on my Windows machine could not confirm…

 
Name (required)
E-mail (required - never shown publicly)
URI
Your Comment (smaller size | larger size)
You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <del datetime="" cite=""> <dd> <dl> <dt> <em> <i> <ins datetime="" cite=""> <kbd> <li> <ol> <p> <pre> <q cite=""> <samp> <strong> <sub> <sup> <ul> in your comment.