OT: Funny Stuff from Pay Pal?

Linux also has a hosts file. The much larger problem on the Windows boxes was a third-party firewall that had a buggy DNS client that did not do anti-spoofing properly and would accept and cache DNS spoofed data from any source without verification.

The paypal 'attack' is nothing new, we were aware of the same problem back in the days of ASCII only DNS, long before SSL was designed some joker registered Micros0ft.com and put up an attack site. The problem identified by Schmoo had actually been anticipated in the design of the DNS multi-lingual extension, in theory it was not possible to register DNS names with names from different character sets. In practice there are some languages where either the Roman or the Cyrilic alphabet may be used. So one of the registrars had a code page up that accepted both if you registered a name in Tidjuk.

Oh and the paypal 'attack' only affected Firefox.

A much bigger problem is the phishing gangs registering bigbank-security.com, bigbank-login.com etc. etc.

Reply to
Phillip Hallam-Baker
Loading thread data ...

Hi Scott,

I never got to thank you for the push sticks. They have come in very handy. I also realize that I need to get a bandsaw sooner than I planned.

Absolutely, we have more than enough people playing whack-a-mole. My job is to work out ways we can fill some of the mole-holes up with cement so that the mole-whackers have a better chance of clobbering 'em.

Reply to
Phillip Hallam-Baker

Just curious... which third-party firewall was that?

-- Regards, Doug Miller (alphageek at milmac dot com)

Nobody ever left footprints in the sands of time by sitting on his butt. And who wants to leave buttprints in the sands of time?

Reply to
Doug Miller

HomeOwnersHub website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.