The blog

Firefox spyware to show up this year?

The Linux/open source publication NewsForge interviewed several security experts who believe that Firefox spyware will show up this year:

Webroot Vice President of Threat Research Richard Stiennon said he expects there will be spyware for Firefox this year, adding that while the browser was designed to be immune from the spyware infecting IE, Firefox will face a new breed of spyware tailored specifically for it.

[…]

Stu Sjouwerman — founder and COO of Counterspy maker Sunbelt Software — agreed that Firefox spyware is likely in 2005.

“I’m pretty sure you can expect one or two Firefox (spyware) exploits before the end of the year,” Sjouwerman said. “The more popular a platform gets, the more likely it is to come under attack. Firefox — which I use myself — I don’t think is going to be immune from that. If you go wide like this, you have to expect that your product will be exposed to a trial by fire.”

Sjouwerman reported that his company’s research on Firefox revealed some Explorer-like situations that may draw spyware.

“We looked into it and found that the security of Firefox had similar openings or vectors where spyware can be utilized to exploit or bypass protection,” he said.

Take all these predictions with a grain of salt, of course. The people quoted in the story have avested interest in keeping computer users in a state of fear and anxiety.

A workaround for the Firefox IDN vulnerability

Update: The fix that is documented in the original advisory and recommended by Mozilla doesn’t work reliably. As soon as you restart Firefox, you;re vulnerable again. Worse, the about:config file continues to show that you’ve properly disabled the setting. This issue is throughly discussed in this thread on the MozillaZine Forums, and the behavior itself is documented in Bugzilla as bug 281365 (you may also see it referenced as bug 281377, but that one is a duplicate).

Thanks to John Walkenbach for pointing out this problem.

I’ve had a chance to work a little more with the vulnerability that affects Firefox and other non-Microsoft browsers. This fix, which was documented in the original advisory, worked for me.

  1. Open Firefox, click in the Address bar, type about:config, and press Enter.
  2. Scroll through the alphabetical list to the entry labeled network.enableIDN.
  3. Double-click that entry to change its value to False.

You don’t need to close or restart Firefox. The change is immediate. Note that any changes you make to default Firefox settings appear in bold in this list. I also expect that a Firefox patch will appear in short order.

Presumably, other Mozilla-based browsers work the same way. At this point there is no known solution for Macintosh Safari users, and the response from Opera (as quoted in the original Shmoo advisory) is that they believe the feature is working properly and plan no changes. Something tells me they’ll change that tune very soon!

Oops! This Firefox security exploit is a doozy

Last month, I predicted that as Firefox became more popular it would face more and more attacks from the Internet’s dark side. A security bulletin issued today appears to identify the first widespread security exploit aimed at non-Microsoft browsers. Ironically, you’re protected if you use Internet Explorer, but you’re vulnerable if you use most Mozilla-based browsers, including Firefox 1.0; this vulnerability also affects Safari 1.2.5 (Macintosh) and Opera 7.54, and perhaps other versions of those browsers as well. Here’s how it works:

You visit an innocent-looking Web page or receive a seemingly authentic e-mail. You click a link that appears to take you to a trusted site (the security advisory uses PayPal as an example) using your default browser, Firefox. The URL in the Address bar says you’re at PayPal’s site, and the locked padlock icon in the lower right corner indicated that you’re on a secure site.

The only trouble is, you’re not at PayPal’s site. You’ve just landed at a site owned by someone who wants to steal your information, and even a careful and suspicious visitor can be fooled by this exploit. The exploit happens because of a flaw in the way these browsers handle “punycode” – links that use codepages and scripts that are similar to Latin-based characters. And the same technique could be used for any site.

A demonstration of the exploit appears here:

http://www.shmoo.com/idn/

Don’t worry, the demo is harmless. But a scam artist who can cut and paste HTML source code can turn the landing page into an exact duplicate of PayPal’s site, or your online banking portal, or a shopping site, or anything they want. This sort of scam will fool a lot of people.

The only indication that you’re not at the correct site appears if you choose the option to use a secure logon and check the security certificate. Even then, you have to dig carefully and look past the opening page of the security dialog box, which appears to display a legitimate security dialog box.

The official security advisory is here. According to one site, there’s a manual fix you can apply to a Firefox configuration file that can block this vulnerability, but I can’t confirm that it works.

(Via Boing Boing and Discourse.net.)

Update: Edited opening paragraph to prevent confusion. See comments for details.

Test your antivirus software

So, you want to show one of your kids or co-workers how your anti-virus software works. You don’t need a live virus to trigger a virus alert. Instead, download a copy of the official antivirus test file from the European Institute for Computer Anti-Virus Research (EICAR). This is a simple text file consisting of a unique string of 68 ASCII characters that you can embed in a file to trigger a reaction from their programs. Note: This is a completely harmless file. The text string doesn’t do anything, and you would never type it by accident, I guarantee!

I won’t post the string here (to avoid setting off warning bells in virus scanners that are set with a hair trigger). But you can find details for creating this file on the EICAR page, along with links to download four different versions of the file. Be sure to download the Zip version of the file to demonstrate what happens when a virus is embedded in a compressed file.

It’s a great educational tool

Anyone out there using Prevx?

I ran across Prevx while researching software to protect Windows users from viruses, adware, and spyware. It promises to “prevent attacks on your computer that other security products don’t even see.”

I plan to test it, of course, but am curious whether anyone out there has personal experience they’d like to share. Add a comment here or send me a note.

Update: Several people sent links to this review of intrusion detection software at Tech Support Alert, which calls Prevx, “Best Free Software Product of 2004.” It’s a pretty thorough evaluation from a site I had never seen before. Gizmo, why not add an RSS feed?

Gmail invites available

I’ve got 50 invitations for Google Mail accounts. If you want one, send an e-mail to edbott AT gmail DOT com. First come, first served.

Make sure you use your real address. My privacy policy is simple: I don’t keep these addresses and I don’t use them for any other purpose or give them to anyone else.

Update: It’s Monday morning and I still have more than 25 left. If you want one, send me a note.

Which Windows e-mail program is best?

In yesterday’s Washington Post, Rob Pegoraro has a review of several e-mail programs that left me scratching my head. Let me see if I can give you the short version. Here’s the intro:

One of the two most widely used programs in this category, Microsoft’s Outlook Express, has not had a meaningful update since 1999, save security fixes for its appalling history of vulnerabilities. The other is Microsoft’s bloated, corporate-centric Outlook, normally sold only with its Office suite for $150 and up. These are not exactly programs that inspire love.

OK, there’s the landscape. Now, he says, “ This dormant market is finally waking up.” The contenders are Eudora and Thunderbird. Here’s what he reports:

  • “Trouble commences with a move from Outlook Express or Outlook.” Eudora mangles address books and settings. Thunderbird doesn’t copy any Outlook settings.
  • “ Eudora is terrific with POP but slow and clumsy with IMAP; Thunderbird’s near-peerless IMAP performance contrasts with POP support that omits a few options handy when checking one account from two computers.”
  • Thunderbird “can’t even check your spelling as you type.”
  • Eudora “ routinely locks up briefly while processing messages and too often crashes outright. The software is confusing to learn … Eudora’s interface – vast amounts of blank space and toolbar icons that appear to have been drawn with crayons – looks ugly.”
  • Both programs try to filter spam, but neither one nails more than half of it.
  • Eudora excels in keeping track of messages, Thunderbird has a “slick message-finding system.”
  • Neither program can compete with Outlook in one crucial way: their address books.

Bottom line: “Considering how Thunderbird has evolved so far, it looks like the e-mail program of the future. But until Thunderbird gains a real address book, I can’t blame users who conclude that Outlook, for all its defects, remains the e-mail program of the present.”

Eudora seems to be a complete straw man here. Why waste half the review on a program that’s ugly and routinely locks up? I would have liked to see a head-to-head comparison between Thunderbird and Outlook, but that wouldn’t have been fair. Outlook is a personal information manager; Thunderbird is a simple e-mail program. What does he mean that Outlook is “bloated”? Does it use too much memory? And as for its “corporate-centric” design, Rob seems to be stuck in 1998. I haven’t worked in a corporate office since 1993, and Outlook is an absolutely indispensable part of my working life. The same is true for my wife, who left corporate life the same time I did and does just about everything in Outlook.

Don’t get me wrong. I like Thunderbird and agree that it’s a worthy alternative to Outlook Express. But I think a lot of the criticism of Outlook, as typified by its quick dismissal in this review, is a legacy of bugs and bad design decisions that plagued earlier editions. Most of the big problems were solved with Outlook 2002 (Office XP). The changes in Outlook 2003 made this a phenomenal productivity suite that does a great job with calendars, contacts and e-mail. In my experience, the program is fast, easy to use, extraordinarily customizable, and rarely if ever crashes.

And Outlook “doesn’t inspire love”? I know a lot of people who don’t work for Microsoft (David Allen, Marc Orchant, Sue Mosher, and a few hundred others) who would disagree.

(Bonus tip for everyone having problems with Outlook 2003 and IMAP: Open the account settings dialog box for your IMAP server and click the More Settings button. On the Advanced tab, slide the Server Timeouts bar all the way to the left, so it’s set at 10 seconds. Previously, I had experienced the same hangs that other people reported,. No longer.)

“Cult of Mac” blogger calls Mac fans “defensive” and “paranoid”

Leander Kahney, who wrote the silly Wired News story about iPods in Redmond that has gotten way more than its 15 minutes of deserved fame, decided to speak up in his The Cult of Mac Blog. Kahney, who writes almost exclusively about Apple and the Mac, says my post that criticized his reporting “was so furious, it reminded me of defensive, paranoid Mac fans.”

Wow, those are pretty strong words. I’d suggest that you Mac fans reading this let Leander know how much you appreciate being called defensive and paranoid. I wouldn’t blame you for being furious. Oh, wait. Leander doesn’t allow comments on his blog.

Please note that comments are still open on my original post and I haven’t censored a single word, even those from people who might reasonably be considered furious, defensive, or just overly passionate. So if you have a message for Leander, I guess you can leave it here.

What’s the Plural of “Virus”?

If you said “virii,”  bzzzzzzzzt!

The correct answer is “viruses.”

I’ve won several rounds of drinks and at least one dinner with this one. Here’s a tip for those who like to make bets: People who insist on saying “virii” are often wine geeks as well, so this is a good topic to bring up when perusing the wine list. If you can get the person across the table to pay for an $80 bottle of wine by winning this bet, it will taste even better.