Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-disclosure] Apple Safari: idn urlbar spoofing |
|---|---|
| Date: | Mon, 25 Jun 2007 23:22:34 +0200 (CEST) |
On Mon, 25 Jun 2007, Larry Seltzer wrote:
It looks different on my system: http://www.larryseltzer.com/safe2.png Safari 3.0.2 on XPSP2
Looks simply like a difference in system fonts used on your machines. The attack relies on padding the hostname with Unicode characters that, for the typeface used, are rendered as white spaces. Whether Safari devs are to blame here exclusively, I'm not sure - IDN concept is by itself pretty evil, and this can be viewed simply a clever take on homograph attacks. /mz _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Full-disclosure] Apple Safari: idn urlbar spoofing, Larry Seltzer |
|---|---|
| Next by Date: | Re: [Full-disclosure] Invitation to connect on LinkedIn, Peter Dawson |
| Previous by Thread: | Re: [Full-disclosure] Apple Safari: idn urlbar spoofing, Larry Seltzer |
| Next by Thread: | Re: [Full-disclosure] Apple Safari: idn urlbar spoofing, Robert Swiecki |
| Indexes: | [Date] [Thread] [Top] [All Lists] |