Phishing attack in Firefox, Palmoon and maybe others.

For discussions about security.
Post Reply
Message
Author
User avatar
tallboy
Posts: 1760
Joined: Tue 21 Sep 2010, 21:56
Location: Drøbak, Norway

Phishing attack in Firefox, Palmoon and maybe others.

#1 Post by tallboy »

I found this in the Palemoon forum:
Phishing Attack Uses Domains Identical to Known Safe Sites

https://www.wordfence.com/blog/2017/04/ ... -phishing/

How to fix this in Firefox and Palemoon, and probably other browsers:
In your firefox location bar, type ‘about:config’ without quotes.
Do a search for ‘punycode’ without quotes.
You should see a parameter titled: network.IDN_show_punycode
Change the value from false to true.

I now use Pale Moon 27.2.1, but I also have a FF 45.0.2 installed, and the codeline in prefs is present in both.

tallboy
True freedom is a live Puppy on a multisession CD/DVD.

purple379
Posts: 157
Joined: Sat 04 Oct 2014, 22:23

Can Phishing be stopped by --

#2 Post by purple379 »

Can Phishing be stopped by using a DNS which automatically limits out the Domain Numbers of Phishers???

I ask this because - OpenDNS (which actually in the US, so not of much value in Europe) claims their Domain Name Servers prevent Pishing somehow.

Is there a similar service in Europe? And is that service really spying on its users??

slavvo67
Posts: 1610
Joined: Sat 13 Oct 2012, 02:07
Location: The other Mr. 305

#3 Post by slavvo67 »

Tallboy:

I'm guessing that fix would go for other Firefox derivatives, as well. Specifically, I reference SeaMonkey.

Best,

Slavvo67

User avatar
8Geee
Posts: 2181
Joined: Mon 12 May 2008, 11:29
Location: N.E. USA

#4 Post by 8Geee »

I had to bust the post. Sorry... carry on
Linux user #498913 "Some people need to reimagine their thinking."
"Zuckerberg: a large city inhabited by mentally challenged people."

User avatar
tallboy
Posts: 1760
Joined: Tue 21 Sep 2010, 21:56
Location: Drøbak, Norway

#5 Post by tallboy »

A little warning regarding punycode set to true: My Palmoon definitely don't like it, some websites which usually uses https, behave unpredictable with punycode enabled. The extension is maybe not fully developed.

So I toggled it back to false with about:config: network.IDN_show_punycode false

There are no big phish in my pond anyway...

tallboy
True freedom is a live Puppy on a multisession CD/DVD.

Post Reply