Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


November 01, 2004

SpoofStick: the Good, the Bad, and the Ugly

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
back to blog index

I heard about a tool called SpoofStick, which is a browser extension for Internet Explorer and Firefox. The good thing about this tool is that it shows you the real URL of the site you're visiting. The tool is designed to help prevent people from falling victim (the bad part) to URL spoof attacks.

The ugly part is that during installation of SpoofStick all instances of Firefox 1.0PR are immediately shut down without so much as any warning, not to mention a prompt to ask if it's all right to do so. I think this is due to a bug because the first time I tried to installed SpoofStick it didn't install itself. I had to try to reinstall it again to get it work with Firefox and when I performed the second installation it didn't close the browser, but instead showed a message in the Extensions dialog that the installation would be completed after Firefox was restarted.

This bug is an ugly problem because, for example, if you had a couple of instances of Firefox open with a dozen or more tabs open in those instances and you hadn't bookmarked the pages yet then too bad. You'll suddenly find yourselves relegated to searching through mounds of browsing history references to find the URLs again, assuming you have history enabled and the references haven't aged out of it yet.

I wrote to the makers of SpoofStick who told me:

"I think that SpoofStick installation behavior is controlled more by how FireFox deals with extensions than with any code specific to SpoofStick. I expect these issues to be fixed by the FireFox team as they release the final version of the browser.

We'll take a look through the code to see if there's anything that we can do on the SpoofStick side to make this process easier and to make sure it's not actually a bug."


The question remains whether this behavior is due to a bug in SpoofStick or a bug in Firefox 1.0PR. I haven't had problems with any other Firefox extensions, so it'll be interesting to learn where the problem actually resides.

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.





Search Security Matters
 
Security Matters
NOVEMBER 2008
       1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30       
or

 Recently in Security Matters
PDF Attack Via Javascript Injection
Make a Comment
Windows 7 Features Cracked Open
Make a Comment
As Expected: New Worm Exploits Latest Windows Hole
Make a Comment
Google's New Android Phone Vulnerable
Make a Comment
Microsoft Releases Rare Out-of-Band Security Patch
Make a Comment

More blogs about technology,
software, and Windows.

Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing