Page 1
Page 1
Started By
Message

Chrome, Firefox, and Opera users beware: This isn’t the apple.com you want

Posted on 4/21/17 at 9:50 am
Posted by Korkstand
Member since Nov 2003
28703 posts
Posted on 4/21/17 at 9:50 am
LINK
quote:

If you're using Chrome, Firefox, or Opera to view websites, you should be aware of a weakness that can trick even savvy people into trusting malicious impostor sites that want you to download software or enter your password or credit card data. The weakness involves the way these browsers display certain characters in the address bar. Until Google released version 58 in the past 24 hours, for instance, Chrome displayed https://www.xn--80ak6aa92e.com/ as https://www.apple.com. The latest versions of Firefox and Opera by default continue to present the same misleading address. As the screenshot above demonstrates, the corresponding website has nothing to do with Apple. Had a malicious attacker registered the underlying xn--80ak6aa92e.com domain, she could have used it to push backdoored software or to trick visitors into divulging passwords or other sensitive information.


Visiting https://www.xn--80ak6aa92e.com/ is safe, and you should actually go there now to see what your address bar shows to see if you are vulnerable.
Posted by LSUtigerME
Walker, LA
Member since Oct 2012
3789 posts
Posted on 4/21/17 at 10:01 am to
quote:

Visiting https://www.xn--80ak6aa92e.com/ is safe, and you should actually go there now....

Posted by Korkstand
Member since Nov 2003
28703 posts
Posted on 4/21/17 at 10:15 am to



I wouldn't steer you guys wrong. I would hope I would get banned if I linked a malware site.
Posted by BaddestAndvari
That Overweight Racist State
Member since Mar 2011
18281 posts
Posted on 4/21/17 at 10:26 am to
phew, just updated chrome to make it show the correct link... that's insane

P.S: For chrome users, you can actually hover over the link Korkstand posted and see what Chrome will show you on the other end, without having to even click on it. Originally it said apple.com - which is terrifying (luckily I just don't click on links... like ever)
Posted by Spock's Eyebrow
Member since May 2012
12300 posts
Posted on 4/21/17 at 10:32 am to
quote:

For chrome users, you can actually hover over the link Korkstand posted and see what Chrome will show you on the other end, without having to even click on it. Originally it said apple.com - which is terrifying (luckily I just don't click on links... like ever)


Ditto for Firefox. I applied the about:config fix the article describes for all my Firefox profiles yesterday.
Posted by trux83LSU
brandon, ms
Member since Dec 2006
2650 posts
Posted on 4/21/17 at 10:40 am to
quote:

P.S: For chrome users, you can actually hover over the link Korkstand posted and see what Chrome will show you on the other end, without having to even click on it. Originally it said apple.com - which is terrifying (luckily I just don't click on links... like ever)

Opera does that as well. When I clicked the link opera tells me its not a legit site though.
Posted by 4WHLN
Drinking at the Cottage Inn
Member since Mar 2013
7579 posts
Posted on 4/21/17 at 10:50 am to
so when I hover over the long link (second one) it says apple.com. So am I in danger here?

Im using Chrome

ETA sorry for the stupid question, just want to make sure I understand.
This post was edited on 4/21/17 at 10:51 am
Posted by Spock's Eyebrow
Member since May 2012
12300 posts
Posted on 4/21/17 at 10:59 am to
quote:

ETA sorry for the stupid question, just want to make sure I understand.


Does ETA'ing it's "stupid" mean you understand now?

(If not, then yes, you should update.)
Posted by Duckismyspiritanimal
Cupertino, CA
Member since Apr 2017
173 posts
Posted on 4/21/17 at 11:00 am to
In this instance, no. The fake apple.com was created by the discloser as a proof of concept. The vulnerability takes advantage of the code to display representations of unicode characters in the browser bar as the unicode character. Chrome and by extension Opera (which is currently built on chromium) is patching this issue. Firefox is still vulnerable.
Posted by Korkstand
Member since Nov 2003
28703 posts
Posted on 4/21/17 at 11:14 am to
quote:

so when I hover over the long link (second one) it says apple.com. So am I in danger here?
You are not in danger by clicking that particular link, but yes, if it shows 'apple.com' then your browser needs to be updated.
Posted by 4WHLN
Drinking at the Cottage Inn
Member since Mar 2013
7579 posts
Posted on 4/21/17 at 11:41 am to
gotcha. I am now updated. thanks for the info
Posted by CENLALSUFAN
Beaumont
Member since Mar 2009
7208 posts
Posted on 4/21/17 at 10:52 pm to
What about mobile? I have a note 5 and it's saying everything is updated but it's still bringing me to the apple.com....
Posted by Korkstand
Member since Nov 2003
28703 posts
Posted on 4/22/17 at 12:38 am to
The mobile browsers will probably be a little behind. My chrome on Android still shows apple, but the chrome canary version seems to be updated. I'd give it a few days. Meanwhile, I wouldn't worry too much about this. As long as you use your bookmarks, type in an address, or stick to trusted sites, you'll be fine.
This post was edited on 4/22/17 at 12:39 am
first pageprev pagePage 1 of 1Next pagelast page
refresh

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on Twitter, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookTwitterInstagram