Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


November 01, 2004

SpoofStick: the Good, the Bad, and the Ugly

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
back to blog index

I heard about a tool called SpoofStick, which is a browser extension for Internet Explorer and Firefox. The good thing about this tool is that it shows you the real URL of the site you're visiting. The tool is designed to help prevent people from falling victim (the bad part) to URL spoof attacks.

The ugly part is that during installation of SpoofStick all instances of Firefox 1.0PR are immediately shut down without so much as any warning, not to mention a prompt to ask if it's all right to do so. I think this is due to a bug because the first time I tried to installed SpoofStick it didn't install itself. I had to try to reinstall it again to get it work with Firefox and when I performed the second installation it didn't close the browser, but instead showed a message in the Extensions dialog that the installation would be completed after Firefox was restarted.

This bug is an ugly problem because, for example, if you had a couple of instances of Firefox open with a dozen or more tabs open in those instances and you hadn't bookmarked the pages yet then too bad. You'll suddenly find yourselves relegated to searching through mounds of browsing history references to find the URLs again, assuming you have history enabled and the references haven't aged out of it yet.

I wrote to the makers of SpoofStick who told me:

"I think that SpoofStick installation behavior is controlled more by how FireFox deals with extensions than with any code specific to SpoofStick. I expect these issues to be fixed by the FireFox team as they release the final version of the browser.

We'll take a look through the code to see if there's anything that we can do on the SpoofStick side to make this process easier and to make sure it's not actually a bug."


The question remains whether this behavior is due to a bug in SpoofStick or a bug in Firefox 1.0PR. I haven't had problems with any other Firefox extensions, so it'll be interesting to learn where the problem actually resides.

End of Article



Reader Comments

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now





Search Security Matters
 
Security Matters
JULY 2009
    1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31  
or

 Recently in Security Matters
Will ICANN Ban Top Level DNS Wildcarding?
Make a Comment
SecureBrowsing Extension for IE and Firefox
Make a Comment
Wireshark 1.2.0 Sports Lots of New Features
Make a Comment
Gmail to go with HTTPS by default

Last Comment
Why was this never an issue with Hotmail...? It's been around a lot longer than Gmail, yet no one s...
(2 Comments)
iPhone Recovery over USB
Make a Comment

More blogs about technology,
software, and Windows.

Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home asp.netPRO Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement | Reprints and Licensing