IE bests rival browsers in at least one area
February 9, 2005 by Mike Wendland
How about this? There’s at least one security issue that Microsoft’s Internet Explorer Web browser apparently is NOT vulnerable to - unlike all the others. Safari, Firefox, Opera struck by spoofing flaw
















Actually the only reason IE isn’t effected is because it incorrectly implements the IDN standard.
The standard is flawed, not the browsers.
And Firefox has already been “patched” by de-activating that feature entirely.
The developers of firefox have corrected the problem, and quickly I might add.
http://ftp.mozilla.org/pub/mozilla.org/firefox/nightly/latest-aviary1.0.1/
Ironic that IE is not vulnerable because MS has been so slow to update IE — I think we should screw this IDN crap, which is trying to please some people by making everyone’s browser resolve these international characters by default. It should not be by default, browsers should use the standard (and historical) 37 characters only by default for resolving domain names. If the user’s native tongue uses special characters, and they want to access sites using IDN, let them turn on that option manually or download a plug in (we have to download Flash and Quicktime, after all, and do we complain about it?).
I don’t see any reasonable way to resolve this otherwise.
O.K., I feel foolish. I just tried the test link at Secunia using the “patched” firefox for OSX and windows. Both failed the test. Apologies to everyone, except the guy who posted the link on boingboing, I hope he still thinks it’s fixed.
Interesting — my OS X Firefox passed the Secunia test after I downloaded the update this morning.
T
Mozilla/5.0 (Macintosh; U; PPC Mac OS X Mach-O; en-US; rv:1.8b) Gecko/20050209 Firefox/1.0+
fails secunia.com’s test.
there is no mention of a nightly build that fixes the issue in the sticky post at the mozillaZine. There are however several suggestions, using extensions and editing config files for firefox.
You must be lucky. what’s your version info ToeKnee?
Mozilla/5.0 (Macintosh; U; PPC Mac OS X Mach-O; en-US; rv:1.7.5) Gecko/20050209 Firefox/1.0
Do you have a nightly build? This is the regular version downloaded today. I am not up on the system of Mozilla’s versioning.
T
it’s the nightly, I tried the standard front page download too though and it failed as well. I just manually edited my compreg.dat file under library - app support. that did the trick for me. I’ll try a new version in a couple of weeks/months and maybe it’ll be fixed for me, til then the compreg.dat fix is easy enough.
thanks for the info T