Closed Bug 284269 Opened 20 years ago Closed 20 years ago

IDN URL doenst change on redirect. (possible url-spoof)

Categories

(Core :: Networking, defect)

x86
Windows 2000
defect
Not set
major

Tracking

()

RESOLVED DUPLICATE of bug 264610

People

(Reporter: dan, Assigned: darin.moz)

References

()

Details

User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.7.6) Gecko/20050225 Firefox/1.0.1 Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.7.6) Gecko/20050225 Firefox/1.0.1 Upon checking out the new "IDN shown as punycode" thingie in 1.0.1 i entered a few random IDN names. All i tested were converted to punycode except: vildtopdræt.dk as far as i can tell, the domain redirects ("Location:") to "http://web.sonofon.dk/22229428/Oegrd-vldt.htm", however the location bar doesnt change AND keeps the "un-encoded" IDN visible. Reproducible: Always Steps to Reproduce: enter vildtopdræt.dk and hit return ;) Actual Results: location bar doesnt change Expected Results: Shown "http://web.sonofon.dk/22229428/Oegrd-vldt.htm" in url.
Well.. I can see the IDN special-char isnt necessarily shown correctly. In HTML domain would be "vildtopdræt.dk"
Over to Darin and core networking... If I click on the URL link above I see the punycode form in the address bar, then the URL is replaced on redirect with the sonofon.dk URL in comment 0. If I copy the URL and paste it into the location bar it doesn't change. If I hit escape then I get the right URL.
Assignee: bugs → darin
Status: UNCONFIRMED → NEW
Component: Location Bar and Autocomplete → Networking
Ever confirmed: true
Product: Firefox → Core
QA Contact: davidpjames → benc
Version: unspecified → Trunk
This is a domain guessing bug (see bug 264610 comment 11). If I enter http://www.vildtopdræt.dk the location bar is updated correctly: nothing to do with IDN at all. *** This bug has been marked as a duplicate of 264610 ***
Group: security
Status: NEW → RESOLVED
Closed: 20 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.