Mozilla disperses confusion about phishy URL threat
By Gina on August 18, 2010 | Computer Security, Mozilla, Firefox, URL, obfuscated links, phishy
Mozilla researchers explained things on the concern that Firefox usually fails to warn users to be cautious of an URL which appears to be malicious one and leads user to misleading and fraudulent websites.
It is known for developers of the open-source browser about the URL bypass since June. However, Firefox will show a warning message which includes a list of obfuscated links that reports these URL has unknown destination. But when users find encoded URLs in online frames embedded in a webpage, no such alert is displayed.
Aditya K Sood on the Armorize blog wrote: „This impacts the user security because obfuscated links in the iframes might trick the user to visit false links“ and also added later „In certain cases, it can be used effectively in spreading malware and stealing sensitive information.“
Mozilla denied this comment and said that they don't believe the behavior represents much of a risk because the obfuscated links aren't visible during normal surfing. Johnathan Nightingale, Mozilla's director of Firefox development stated: „Most users don't look at the HTML source of the pages they are loading, which is the only way you'd encounter this URL. We do not anticipate this bug would cause user confusion or deception.“
More Computer Security news
Adobe news: Sandboxed Flash Player for Firefox released
This week Adobe launched a beta version of Flash Player for Firefox. This version is better for its sandbox feature. A platform security strategist at Adobe, Peleus Uhley said in a blog: "The design of this sandbox is similar to what Adobe delivered with Adobe Reader X Protected Mode and follows the same Practical Windows Sandboxing approach. Read more.- How to get PDF secured?
- 'Nazileaks' site is hacked by hacker group Anonymous
- Spywared.com wishes you happy holidays!
- Silent IE updates
- Anonymous and Team Poison duet create Operation Robin Hood
- Unprotected data still remains at British businesses
- 12 vulnerabilities are fixed by Adobe
- Be ready for Halloween scare on Internet: avoid scam attacks
- Who's fault is the mess on Youtube?
- Survey reveals overconfidence about security systems








