Attn: Non IE Browser Users, Magic Mushroom cultivation, Magic Mushroom spores, Magic Mushroom cultivation,South American,Amazon,curandero,shaman,inebrians,cabrerana,Psychotria,rusbyana,Banisteriopsis,ayahuasca,hoasca,vine of the dead,vine of souls,DMT,ayahuasca, chacruna, caapi, yage, challiponga,huasca,mushroom, mush, psilocybin, psilocin, drugs, pedro, san pedro, psilocybe, cubensis, fanaticus, mycology, hallucinogens, mushroom spores, spores, psilocybe mushrooms, mushroom, mushrooms, spore, mushroom pictures, psilocybin, psilocybe, psilocin, mushroom spores, magic mushroom spores, sacred mushroom spores, rare mushroom spores, spiritual mushroom spores, wild mushroom spores, scientific research mushroom spores, mushroom cultivation, shroomery, ralphsterspores, thehawkseye, sporelab, sacredshrooms, nan's nook, nook, the little guy, high times, overgrow, mycotopia" /> Attn: Non IE Browser Users General Discussions" /> <font color="ff0000">Attn: Non IE Browser Users</font> - Mycotopia Web Forums
Mycotopia Web Forums

Go Back   Mycotopia Web Forums > Board Discussions > General Discussions

Notices

General Discussions Unsure where to post ? Start here...


Reply
 
Thread Tools Display Modes
Old 02-09-05, 19:45   #1 (permalink)
Mycotopiate
 
imok's Avatar
 
Join Date: Dec 1971
Posts: 385
imok LEVEL 0 - UNRATED
Non IE browser vulnerability you should be aware of.
From: TOURBUS Volume 10, Number 48 -- 7 Feb 2005
Link: http://www.TOURBUS.com

quote:

-------------------------------------------------- --
New Browser Spoofing Vulnerability
Audience: Everyone who DOESN'T use Internet Explorer
-------------------------------------------------- --

It looks like there is a new browser spoofing vulnerability that--brace yourself--DOESN'T affect Internet Explorer. No, really. Affected browsers include Mozilla, Firefox, Safari, Netscape Navigator, and Opera on both PCs and Macs. But NOT Internet Explorer.

The vulnerability displays fake domain names in both hyperlinks and your browser's address bar. Is this earth-shattering? No. Should you lose sleep over it? No. Should you at least know a little about it in order to protect your personal information should something strange happen? ABSOLUTELY!

To see this vulnerability in action, check out
http://www.netsquirrel.com/articles/mozilla_spoofi ng.html

Now for the REALLY bad news: There's no way to fix this problem. Yet. [Setting network.enableIDN to false in about:config doesn't work and even SpoofStick is fooled by these fake URLs, despite rumors to the contrary floating around the blogsphere.] Should you panic? As I said, no! But, until the browser gurus find a fix, you should take the following precautions:

1. DON'T TRUST HYPERLINKS IN HTML-FORMATTED EMAIL MESSAGES (emails that display images and hyperlinks and look very much like web pages) even if those email messages are from your friends or family. This is especially true for hyperlinks in email messages from Amazon, AOL, eBay, PayPal, your bank, your credit card company, or any other company you normally do
business with. If any web site, financial company, or commercial entity sends you an email asking you to click on a hyperlink in that email to update your account information, DO NOT CLICK ON THAT LINK. Because of this new spoofing vulnerability, you simply cannot trust hyperlinks in HTML-formatted emails to point to the correct URL.

2. BE SUSPICIOUS OF HYPERLINKS ON WEB PAGES YOU HAVE NEVER VISITED BEFORE. To be completely honest, the chance of you running into a spoofed URL on a web page is pretty slim, and the chance is all but zero on the big .com sites you visit every day. More likely than not, the criminals will be spoofing URLs in email messages, not on Web pages. But, if you are at a web page you have never visited before, exercise a little caution. If something feels wrong, leave.

3. THE BEST WAY TO AVOID BEING HIJACKED BY A SPOOFED URL IS TO MANUALLY TYPE THE URL USING YOUR BROWSER'S ADDRESS BAR. Remember, the spoof only affects hyperlinks in email messages and web pages, not addresses you manually key in to your browser's address bar. So,to be really safe, if you need to access your account information at Amazon, AOL, eBay, PayPal, your bank or financial institution, your credit card company, or any other company you normally do business with, manually enter the URL.

And stay tuned to Tourbus. When the browser manufacturers release patches, I'll make sure to tell you about them in one of my posts.
__________________
Hope this helps :)
imok is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 02-09-05, 20:25   #2 (permalink)
Mycophage
 
shamrox's Avatar
 
Join Date: Feb 1973
Posts: 108
shamrox LEVEL 0 - UNRATED
Thanks for the heads up Imok! I got an email from "paypal" a few months ago, asking me to update my information. I was about half way through the website when I got leary, and checked into it further. I notified paypal, and they assured me that it wasn't them. I changed my password and login, even though I didn't fully complete the information they were asking for. What really made me think twice was when they asked me for my debit cards pin number. Hmmmm...Maybe I should have realized it before then, but whats a stoner to do.

So be careful everyone!!
shamrox is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Bookmarks

Tags
attn, browser, users

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Attn: Triton THELITTLEGUY General Discussions 7 05-21-05 06:07
attn: south floridians grasshopper wilkins General Discussions 16 03-08-05 16:21
Attn all mycotopes with avatars by Sinthetic. A way to say thank you... hellosidney2010 General Discussions 18 02-25-05 16:21
resist/rebel Archive through January 18, 2004 roo The Shroom Dump 556 04-22-04 04:14


All times are GMT -5. The time now is 09:30.

Mycotopia Web Forums


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0


All trademarks are © their respective owners, all other content is © Mycotopia 2000/2008
Site Designed and Hosted By | Zen Media Studios




[Output: 55.45 Kb. compressed to 53.29 Kb. by saving 2.16 Kb. (3.89%)]