CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer

Firefox 3 and PIRT/MIRT

 
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1725
Location: Japan
Premium

PostPosted: Thu Jun 19, 2008 4:30 am    Post subject: Firefox 3 and PIRT/MIRT
Reply with quote

Before submitting anything to PIRT/MIRT I always check if the URL in question is still active, or if the object in question has already been removed. I see no point of submitting anything that has already been resolved.

Firefox 3 does not give me that option anymore. I wanted to check if hxxp://customcars.com.br/index1.php is still active, but all I get from FF3 is a pop-up

Quote:
The website at customcars.com.br has been reported as a web forgery designed to trick users into
sharing personal or financial information.

Clicking OK will just show a blank page, and I have no way to determine if the site/page is still active.

Great for "ordinary" users, but useless for my purpose. I will investigate if there is a way to allow the website (or return code) to be displayed.




alert.png
 Description:
Firefox 3 alert.
 Filesize:  8.45 KB
 Viewed:  587 Time(s)

alert.png


Back to top
View users profile Send private message Visit posters website
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1725
Location: Japan
Premium

PostPosted: Thu Jun 19, 2008 4:39 am    Post subject:
Reply with quote

OK, it can be deactivated under Tools | Options | tab Security

  • Tell me if the site I'm visiting is a suspected attack site
  • Tell me if the site I'm visiting is a suspected forgery




FF3security.png
 Description:
FF3 security options.
 Filesize:  31.85 KB
 Viewed:  28 Time(s)

FF3security.png


Back to top
View users profile Send private message Visit posters website
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1725
Location: Japan
Premium

PostPosted: Thu Jun 19, 2008 4:50 am    Post subject:
Reply with quote

The trouble is that if I disable these options, then I don't know if the site has already been reported (Help | Report web forgery).

It seems there is no option to show the Alert and the actual web site.

Back to top
View users profile Send private message Visit posters website
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1725
Location: Japan
Premium

PostPosted: Thu Jun 19, 2008 5:06 am    Post subject:
Reply with quote

It's probably one of the about:config settings, but I have no idea which one. I wonder if these are documented anywhere?

Back to top
View users profile Send private message Visit posters website
downie

PIRT Handler


Joined: May 19, 2006
Posts: 3743

Phishing Squad

PostPosted: Thu Jun 19, 2008 7:45 am    Post subject:
Reply with quote

Prefixing the URL with view-source: may bypass the phish filtering
(it does on FF2).
In about:config you can search for safebrowsing?


_________________
"For evil to triumph utterly, it is only necessary that good men do nothing"
Back to top
View users profile Send private message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1725
Location: Japan
Premium

PostPosted: Thu Jun 19, 2008 9:19 am    Post subject:
Reply with quote

downie wrote:
Prefixing the URL with view-source: may bypass the phish filtering
(it does on FF2).

Thanks! Just tried; it seems not to do that in FF3 (same behavior as without the prefix).
downie wrote:
In about:config you can search for safebrowsing?

This returns a few lines, but I am not really sure what is what...




safebrowsing.png
 Description:
FF3 safebrowsing.
 Filesize:  37.76 KB
 Viewed:  34 Time(s)

safebrowsing.png


Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer