After an evaluation, GNOME has moved from Bugzilla to GitLab. Learn more about GitLab.
No new issues can be reported in GNOME Bugzilla anymore.
To report an issue in a GNOME project, go to GNOME GitLab.
Do not go to GNOME Gitlab for: Bluefish, Doxygen, GnuCash, GStreamer, java-gnome, LDTP, NetworkManager, Tomboy.
Bug 123712 - Fraud prevention feature
Fraud prevention feature
Status: RESOLVED FIXED
Product: galeon
Classification: Deprecated
Component: general
1.3.9
Other Linux
: Normal enhancement
: ---
Assigned To: galeon-maint
Yanko Kaneti
Depends on:
Blocks:
 
 
Reported: 2003-10-02 15:19 UTC by Mark Howard
Modified: 2004-12-22 21:47 UTC
See Also:
GNOME target: ---
GNOME version: ---



Description Mark Howard 2003-10-02 15:19:03 UTC
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=212755 requests:

Please forward upstream:

Every HTTP URL can be written in the form username:password@host
It is very possible that username could be filled in with something that 
looks like a legitimate host, and host could be filled in with a 
malicious host. An example of this:
http://www.citibank.com:ac=VybznNffNxknAUxPrfE2jYaQUptJ@a3ksd.PiSeM.NeT/

This real fraud site has disguised its malicious host in such a way that 
most ordinary users would not recognize that it is not really 
citibank.com's website.

It has been reported (in discussion on vox-tech@lists.lugod.org) that 
Opera has a feature where specifying a username in the URL will cause a 
dialog box to pop up warning of this, like so:

Security warning:

You are about to go to an address containing a username.

  Username: www.citibank.com
  Server: a3ksd.pisem.net

Are you sure you want to go to this address?

Could you add a feature like this to Galeon to help users more easily 
protect themselves against fraud?
Comment 1 Tommi Komulainen 2003-10-02 16:51:49 UTC
http://bugzilla.mozilla.org/show_bug.cgi?id=122445
Comment 2 Mikael Magnusson 2004-07-08 22:47:18 UTC
I'm pretty sure this is implemented in mozilla 1.7, i get a dialog box warning
me that i'm going to a3ksd.whatever and not citibank.com. however, clicking No
still opens the site....
Comment 3 Crispin Flowerday (not receiving bugmail) 2004-12-18 23:18:32 UTC
This is properly fixed in 1.7.5:

https://bugzilla.mozilla.org/show_bug.cgi?id=263263