Mozilla eases fears over phishy URL alert
Mozilla developers have eased concerns about the severity of a security feature in Firefox that often fails to warn users when they've encountered obfuscated URLs that might lead to malicious websites. Developers of the open-source browser have known of the URL warning bypass since at least June, when it was reported here. Under …
Old link
The link Sood referred to is for a vulnerability that was fixed before chrome reached version 1 (it's specifically referring to version 0.2.149.xx, some of the earlier beta builds). It's now at version 6 in the dev branch, and should be released as version 6 within the next few weeks.
The fact that Google felt this was worthwhile to patch nearly two years ago should tell them something. At the very least they should have checked to see if that flaw still existed before making themselves look silly in an attempt to downplay the fact that their browser was found to be vulnerable to it.
Obfuscating URLs which aren't displayed?
AFAIK obfuscated URLs are only used to reassure the user that they are visiting one site when in fact they're visiting another by showing something which looks legit in the address bar but isn't (using some of the more exotic syntax features that URLs offer).
What would be the benefit of obfuscating a URL in an iframe? Iframes don't have address bars and the browser's phishing filter would display a warning anyway. If a browser does put obfuscation protection on iframes then it can be gotten round by not obfuscating it.
Or is there something I'm missing?
Sign up, sign up for The Register's weekly IT security newsletter - click here
Popular Whitepapers
- The BI Inflexion Point
Information is a right, not a privilege - VPN security - if you want it, come and get it
Attention WiFi hotspotters: You want it - The Register Guide to iSCSI
A primer on Internet SCSI, a protocol to transport SCSI commands over IP - Secure Mobile Working
Beyond the Technology - The Impact of IT Security Attitudes
Putting the pieces in place for effective security delivery - The Register guide to unified communications
A primer on the implications of unified communications for enterprise IT


