<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Firefox 2.0.0.12 SSL Spoofing and Domain Guessing flaws! in Security</title>
<link>http://www.dslreports.com/forum/r19944847</link>
<description></description>
<language>en</language>
<pubDate>Wed, 02 Dec 2009 08:47:58 EDT</pubDate>
<lastBuildDate>Wed, 02 Dec 2009 08:47:58 EDT</lastBuildDate>

<item>
<title>Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing flaws!</title>
<link>http://www.dslreports.com/forum/remark,19949475</link>
<description><![CDATA[<A HREF="/useremail/u/322004"><b>pepperxn</b></A> : <div class="bquote"><small>said by  antdude <A HREF="/useremail/u/352846"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br><div class="bquote"><small>said by  chachazz <A HREF="/useremail/u/914341"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Name: Firefox 2.0.0.12 &#9;<br>Scheduled Release Date : February 7<br><A HREF="http://wiki.mozilla.org/Releases"><u>Release Schedule</u></a><br> </div>Ooh. Hmmph, no suite product SeaMonkey? :(<br> </div>SeaMonkey 1.1.8 is coming soon.<br><br>&raquo;<A HREF="http://home.kairo.at/blog/2008-02/weekly_status_report_w05_2008" >home.kairo.at/blog/2008-02/weekl&middot;&middot;&middot;w05_2008</A><br><br>Notice this sentence: "I created and uploaded (two sets of) candidate builds for SeaMonkey 1.1.8 this week, which is our upcoming security release for the stable 1.1.x series. We target a release nearly in sync with Firefox 2.0.0.12 this Thursday or Friday."]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19949475</guid>
<pubDate>Thu, 07 Feb 2008 04:41:50 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing flaws!</title>
<link>http://www.dslreports.com/forum/remark,19949274</link>
<description><![CDATA[<A HREF="/useremail/u/352846"><b>antdude</b></A> : <div class="bquote"><small>said by  chachazz <A HREF="/useremail/u/914341"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Name: Firefox 2.0.0.12 &#9;<br>Scheduled Release Date : February 7<br><A HREF="http://wiki.mozilla.org/Releases"><u>Release Schedule</u></a><br> </div>Ooh. Hmmph, no suite product SeaMonkey? :(<br><small>--<br>Ant @ &raquo;<A HREF="http://antfarm.ma.cx" >antfarm.ma.cx</A> and &raquo;<A HREF="http://aqfl.net" >aqfl.net</A>. Please do not IM/e-mail me for technical support. Use the forum! Disclaimer: The views expressed in this posting are mine, and do not necessarily reflect the views of my employer</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19949274</guid>
<pubDate>Thu, 07 Feb 2008 02:00:54 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing flaws!</title>
<link>http://www.dslreports.com/forum/remark,19949264</link>
<description><![CDATA[<A HREF="/useremail/u/914341"><b>chachazz</b></A> : Name: Firefox 2.0.0.12 &#9;<br>Scheduled Release Date : February 7<br><A HREF="http://wiki.mozilla.org/Releases"><u>Release Schedule</u></a><br><small>--<br>Gladiator Security Forum: <A HREF="http://www.gladiator-antivirus.com/">www.gladiator-antivirus.com/</a><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19949264</guid>
<pubDate>Thu, 07 Feb 2008 01:54:36 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing flaws!</title>
<link>http://www.dslreports.com/forum/remark,19949258</link>
<description><![CDATA[<A HREF="/useremail/u/352846"><b>antdude</b></A> : <div class="bquote"><small>said by  La Luna <A HREF="/useremail/u/429050"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br><div class="bquote"><small>said by  jansson_mark <A HREF="/useremail/u/444625"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Dude, the version is still 2.0.0.11.<br> </div>&raquo;<A HREF="/forum/r19921186-Firefox-2012-VS-IE7">Firefox 2.0.12 VS IE7</A><br><br>&raquo;<A HREF="http://wiki.mozilla.org/Releases/Firefox_2.0.0.12" >wiki.mozilla.org/Releases/Firefox_2.0.0.12</A><br><br>&raquo;<A HREF="http://ftp.eu.mozilla.org/pub/mozilla.org/firefox/tinderbox-builds/pacifica-vm-mozilla1.8/?C=M;O=D" >ftp.eu.mozilla.org/pub/mozilla.o&middot;&middot;&middot;?C=M;O=D</A><br> </div>Soon. Should be any day assuming no release blockers.<br><small>--<br>Ant @ &raquo;<A HREF="http://antfarm.ma.cx" >antfarm.ma.cx</A> and &raquo;<A HREF="http://aqfl.net" >aqfl.net</A>. Please do not IM/e-mail me for technical support. Use the forum! Disclaimer: The views expressed in this posting are mine, and do not necessarily reflect the views of my employer</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19949258</guid>
<pubDate>Thu, 07 Feb 2008 01:51:22 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing flaws!</title>
<link>http://www.dslreports.com/forum/remark,19949180</link>
<description><![CDATA[<A HREF="/useremail/u/429050"><b>La Luna</b></A> : <div class="bquote"><small>said by  jansson_mark <A HREF="/useremail/u/444625"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Dude, the version is still 2.0.0.11.<br> </div>&raquo;<A HREF="/forum/r19921186-Firefox-2012-VS-IE7">Firefox 2.0.12 VS IE7</A><br><br>&raquo;<A HREF="http://wiki.mozilla.org/Releases/Firefox_2.0.0.12" >wiki.mozilla.org/Releases/Firefox_2.0.0.12</A><br><br>&raquo;<A HREF="http://ftp.eu.mozilla.org/pub/mozilla.org/firefox/tinderbox-builds/pacifica-vm-mozilla1.8/?C=M;O=D" >ftp.eu.mozilla.org/pub/mozilla.o&middot;&middot;&middot;?C=M;O=D</A><br><small>--<br><b><A HREF="http://www.thereligionofpeace.com/">10,504 DEADLY TERROR ATTACKS SINCE 9/11</a></b>~~<b><A HREF="/forum/disco">TEAM DISCOVERY</a></b><br><i>Can't feel you anymore, don't need you anymore, don't believe you anymore, I don't need you anymore</i><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19949180</guid>
<pubDate>Thu, 07 Feb 2008 01:06:07 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing flaws!</title>
<link>http://www.dslreports.com/forum/remark,19949112</link>
<description><![CDATA[<A HREF="/useremail/u/322004"><b>pepperxn</b></A> : 2 flaws here.<br><br>&raquo;<A HREF="http://www.0x000000.com/?i=509" >www.0x000000.com/?i=509</A><br><br>and<br><br>&raquo;<A HREF="http://www.0x000000.com/index.php?i=511" >www.0x000000.com/index.php?i=511</A><br>&raquo;<small>https</small>://<A HREF="https://bugzilla.mozilla.org/show_bug.cgi?id=415034">bugzilla.mozilla.org/show_bug.cgi?id=415034</A><br><br>Haven't found the bug # for the first one yet. 2nd one has a patch, and will be fixed in 1.8.1.13 (Firefox 2.0.0.13).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19949112</guid>
<pubDate>Thu, 07 Feb 2008 00:40:04 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing flaws!</title>
<link>http://www.dslreports.com/forum/remark,19947585</link>
<description><![CDATA[<A HREF="/useremail/u/819609"><b>Grail Knight</b></A> : So are you testing the beta in hopes of informing Mozilla Foundation that they need to work on the beta? <br><br>The beta is 2.0.0.12pre.<br><br>The release is 2.0.0.11<br><small>--<br>"We must look for consistency. Where there is a want of it we must suspect deception." - Sherlock Holmes</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19947585</guid>
<pubDate>Wed, 06 Feb 2008 20:14:24 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing flaws!</title>
<link>http://www.dslreports.com/forum/remark,19947475</link>
<description><![CDATA[<A HREF="/useremail/u/547118"><b>Epyon9283</b></A> : What the heck are you talking about?<br><br>What comes after the @ is the host name that firefox is going to connect to. If that host has a valid, trusted SSL cert you're not going to see a warning message. What are you spoofing?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19947475</guid>
<pubDate>Wed, 06 Feb 2008 19:53:20 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing flaws!</title>
<link>http://www.dslreports.com/forum/remark,19947428</link>
<description><![CDATA[<A HREF="/useremail/u/831732"><b>WeenieBoy</b></A> : Besides the wrong version with this "problem" What are you saying ? When I did it I got the certificate from the rogue host so how the heck is that wrong ? What does "legit" mean ?<br><br>I am confused about your post ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19947428</guid>
<pubDate>Wed, 06 Feb 2008 19:44:41 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing flaws!</title>
<link>http://www.dslreports.com/forum/remark,19945399</link>
<description><![CDATA[<A HREF="/useremail/u/444625"><b>jansson_mark</b></A> : Dude, the version is still 2.0.0.11.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19945399</guid>
<pubDate>Wed, 06 Feb 2008 14:05:08 EDT</pubDate>
</item>

<item>
<title>Firefox 2.0.0.12 SSL Spoofing and Domain Guessing flaws!</title>
<link>http://www.dslreports.com/forum/remark,19944847</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Firefox seems to have trouble with defining the proper hostname when<br>requesting a ssl connection. I was able to trick Firefox in thinking<br>the hostname behind the at-sign is legit and the same as the URI that<br>requested an ssl connection, and this without a warning.<br><br>PoC: <br><textarea name="code" class="text" cols=50 rows=10>https://www.gmail.com%C0%AF%C0%AF%C0%C0%80@roguehost.com&#012;</textarea><!--end code block-->You can add as much garbage between .com and the @ sign.<br><br>So what else can we do?<br><br>PoC:<br><textarea name="code" class="text" cols=50 rows=10>www.cnn.com%C0%AF%C0%AF%C0%C0%80@google&#012;www.gmail.com%C0%AF%C0%AF%C0%C0%80@hotmail&#012;</textarea><!--end code block-->ah heck we don't need that at all:<br><textarea name="code" class="text" cols=50 rows=10>www.gmail.comxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx@hotmail&#012;</textarea><!--end code block-->works fine also :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19944847</guid>
<pubDate>Wed, 06 Feb 2008 12:28:32 EDT</pubDate>
</item>

</channel>
</rss>
