Advertisement
Promo

Office applications Toolkit

Opera fixes IDN 'vulnerability'

Munir Kotadia ZDNet Australia

Published: 28 Feb 2005 09:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Norwegian software developer Opera released a second beta version of its browser on Saturday. Beta 2 plugs a recently discovered vulnerability that could be used in phishing attacks.

The problem arose because certain browsers support a standardised way of representing domain names in the letters or characters of any language. The Internationalised Domain Names (IDN) vulnerability, which affects non-Microsoft browsers such as Opera, Apple's Safari and Firefox, could help phishers create legitimate-looking Web sites.

Christen Krogh, vice-president of engineering at Opera, explained that when visiting secure Web sites, the browser will now display a yellow security bar containing the name of the organisation owning the site’s security certificate and only display ‘trusted’ top level domains (TLDs).

"One of the most important measures to counter phishing attacks is the use of security certificates. The challenge for browser vendors is to better explain the verification of certificates and to make the user more aware of this additional verification before entering into secure transactions," said Krogh.

To specifically address the IDN vulnerability, Opera's updated browser will only display certain TLDs that have been registered with the company.

According to a statement from Opera, the company "will regularly update its list of trusted TLDs, ensuring maximum protection and the best possible user experience".

In addition to improved security, Opera has made Beta 2 easier to customise and added support for Atom newsfeeds. The browser is available for download from the Opera Web site.

The Mozilla Foundation last week updated its Firefox Web browser to fix the IDN vulnerability, among other bugs.

Is your browser vulnerable to the IDN issue? Security Web site Secunia has constructed a test that can check if your browser is affected.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
100 out of 182 people found this useful


Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Discussions

kavurt kavurt

Taking Out the Skype Garbage

Sunday 15 November 2009, 8:45 PM

7 comments
Xwindowsjunkie Xwindowsjunkie

Karmic Koala Krashes

Sunday 15 November 2009, 7:13 PM

3 comments
Tezzer Tezzer

Here we go again :(

Sunday 15 November 2009, 5:32 PM

6 comments
Tezzer Tezzer

Karmic Koala Krashes

Sunday 15 November 2009, 5:21 PM

3 comments

Vista Upgrade Blog

Windows 7 pricing all over the shop..a...

I really think Microsoft have made a mess of Windows 7 pricing. They got the product right, yet there initial pricing of at around £44.95 for the full version of Windows 7 Home Premium... More

7 comments

Adobe Reader in the Enterprise

This week I had the pleasure of working with some of the Microsoft Premier Field Engineers (PFE's) in an effort to further understand some of the application compatibility issues that... More

Post a comment

No Email Program in Windows 7???????

This has got to be a joke (albeit a very bad one). Or an oversight. A mistake, maybe? Is there really NO EMAIL PROGRAM IN WINDOWS 7????? Not even Microsoft is that stupid, are they?... More

14 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters