PDA

View Full Version : Major Browser Vulnerability



A TIN OF FEAR
7th February 2005, 09:56 AM
in everything but IE...

This is scary. (http://www.shmoo.com/idn/) and I'm hoping its fixed real soon, 'xcept there seems to be some reticence on behalf of the browser manufacturers.

<blockquote>We believe we have correctly implemented IDN, and will not be
making any changes.
<div align="right">Opera</div></blockquote>

Well that sucks. time to start using IE again. or not. there is a workaround for Firefox.

1) Goto your Firefox address bar. Enter about:config and press enter. Firefox will load the (large!) config page.

2) Scroll down to the line beginning network.enableIDN -- this is International Domain Name support, and it is causing the problem here. We want to turn this off -- for now. Ideally we want to support international domain names, but not with this problem.

3) Double-click the network.enableIDN label, and Firefox will show a dialog set to 'true'. Change it to 'false' (no quotes!), click Ok. You are done.

3) Go check out the shmoo demo (http://www.shmoo.com/idn/) again and notice it no longer works.

Good luck!