UNSOLVED

ky331

updated

9 years ago

K

ky331

5 Journeyman

15622 Posts

45048 Points

0

1631

April 17th, 2017 13:00

PunyCode phishing attack

Firefox, Chrome and Opera (but NOT IE, Edge, Safari nor Vivaldi) are currently subject to a phishing attack using "Punicode" characters.   (I've seen conflicting comments about whether or not PaleMoon is impacted...)

Users of Firefox can get around this by going to the address bar, typing

about:config

hit ENTER.   FF warns that "This might void your warranty".   It's okay... just Accept the risk.

In the search box, type

punycode

and a line that reads network.IDN_show_punycode will appear. 

By default, it is set to false. Double-clicking the words will change it to true.

For more details, see https://www.bleepingcomputer.com/news/security/chrome-firefox-and-opera-vulnerable-to-undetectable-phishing-attack/

and/or

https://www.forbes.com/sites/leemathews/2017/04/17/chrome-and-firefox-adding-protection-against-this-nasty-phishing-trick/

-------------------------------------------------------------------------------------------------------

Remark:  This about:config "configuration" is available in PaleMoon... as noted, I've seen some comments that recommend implementing it, while others say it's not necessary to do so.