IDN Phishing ‘Solved’

Heard of the latest ‘bug’ to hit the browser world? Well unless you know what IDN is, probably not. There’s a problem with IDN that results in a certain combination of characters ‘morphing’ themselves into what looks like a valid English site. (I’m stepping outside my realm of knowledge here, so forgive the crazy talk)…. Anyhow, it’s a way for someone to perhaps fool you into thinking you’re on Paypal’s website when you look at your browser’s address bar, but you’re actually redirected elsewhere….

The only fixes right now are to either:

  • disable IDN support, not a nice option for those who need IDN (go here for Firefox, Opera has no such capability, and only IE doesn’t support IDN natively),
  • install/configure a proxy like Proxomitron which will work for everyone and warn you of ‘questionable’ URLs, or
  • a workaround for Firefox using the AdWatch extension. Another non-ideal option for those who need IDN