Showing posts with label Opera. Show all posts
Showing posts with label Opera. Show all posts

Friday, April 21, 2017

This Phishing Attack is Almost Impossible to Detect On Chrome, Firefox and Opera


Monday, April 17, 2017 Mohit Kumar





A Chinese infosec researcher has reported about an "almost impossible to detect" phishing attack that can be used to trick even the most careful users on the Internet.

He warned, hackers can use a known vulnerability in the Chrome, Firefox and Opera web browsers to display their fake domain names as the websites of legitimate services, like Apple, Google, or Amazon to steal login or financial credentials and other sensitive information from users.

What is the best defence against phishing attack? Generally, checking the address bar after the page has loaded and if it is being served over a valid HTTPS connection. Right?



Okay, then before going to the in-depth details, first have a look at this demo web page (note: you may experience downtime due to high traffic on demo server), set up by Chinese security researcher Xudong Zheng, who discovered the attack.

“It becomes impossible to identify the site as fraudulent without carefully inspecting the site's URL or SSL certificate.” Xudong Zheng said in a blog post.If your web browser is displaying "apple.com" in the address bar secured with SSL, but the content on the page is coming from another server (as shown in the above picture), then your browser is vulnerable to the homograph attack.

There is another proof-of-concept website created by security experts from Wordfence to demonstrate this browsers' vulnerability. It spoof "epic.com" domain.

Homograph attack has been known since 2001, but browser vendors have struggled to fix the problem. It’s a kind of spoofing attack where a website address looks legitimate but is not because a character or characters have been replaced deceptively with Unicode characters.

Many Unicode characters, which represents alphabets like Greek, Cyrillic, and Armenian in internationalised domain names, look the same as Latin letters to the casual eye but are treated differently by computers with the completely different web address.

For example, Cyrillic "а" (U+0430) and Latin "a" (U+0041) both are treated different by browsers but are displayed "a" in the browser address.


Punycode Phishing Attacks
By default, many web browsers use ‘Punycode’ encoding to represent unicode characters in the URL to defend against Homograph phishing attacks. Punycode is a special encoding used by the web browser to convert unicode characters to the limited character set of ASCII (A-Z, 0-9), supported by International Domain Names (IDNs) system.

For example, the Chinese domain "短.co" is represented in Punycode as "xn--s7y.co".

According to Zheng, the loophole relies on the fact that if someone chooses all characters for a domain name from a single foreign language character set, resembling exactly same as the targeted domain, then browsers will render it in the same language, instead of Punycode format.



This loophole allowed the researcher to register a domain name xn--80ak6aa92e.com and bypass protection, which appears as “apple.com” by all vulnerable web browsers, including Chrome, Firefox, and Opera, though Internet Explorer, Microsoft Edge, Apple Safari, Brave, and Vivaldi are not vulnerable.

Here, xn-- prefix is known as an ‘ASCII compatible encoding’ prefix, which indicates web browser that the domain uses ‘punycode’ encoding to represent Unicode characters, and Because Zheng uses the Cyrillic "а" (U+0430) rather than the ASCII "a" (U+0041), the defence approach implemented by web browser fails.

Zheng has reported this issue to the affected browser vendors, including Google and Mozilla in January.


Fake Page (top) and Original Apple.com (bottom), but exactly same URL
While Mozilla is currently still discussing a fix, Google has already patched the vulnerability in its experimental Chrome Canary 59 and will come up with a permanent fix with the release of Chrome Stable 58, set to be launched later this month.

Meanwhile, millions of Internet users who are at risk of this sophisticated hard-to-detect phishing attack are recommended to disable Punycode support in their web browsers in order to temporarily mitigate this attack and identify such phishing domains.


How to Prevent Against Homograph Phishing AttacksFirefox users can follow below-mentioned steps to manually apply temporarily mitigation:

Type about:config in address bar and press enter.
Type Punycode in the search bar.
Browser settings will show parameter titled: network.IDN_show_punycode, double-click or right-click and select Toggle to change the value from false to True.Unfortunately, there is no similar setting available in Chrome or Opera to disable Punycode URL conversions manually, so Chrome users have to wait for next few weeks to get patched Stable 58 release.

Although, there are some third-party Chrome extensions/add-ons available on App Store that users can install to get alerts every time they came across any website with Unicode characters in the domain.

Meanwhile, one of the best ways to protect yourself from homograph attacks is to use a good password manager that comes with browser extensions, which automatically enter in your login credentials for the actual domains to which they are linked.

So, whenever you came across any domain which looks like legitimate "apple.com" or "amazon.com" but actually is not, your password manager software will detect it and will not automatically authenticate you to that phishing site.

Moreover, Internet users are always advised to manually type website URLs in the address bar for important sites like Gmail, Facebook, Twitter, Yahoo or banking websites, instead of clicking any link mentioned on some website or email, to prevent against such attacks.

Friday, March 24, 2017

Opera Mini gets redesigned for faster browsing, to cater to Android users in India

Opera Mini gets redesigned for faster browsing, to cater to Android users in India

A new update for Opera Mini on Android has been announced which includes new features specially designed for Indian smartphone users. The new version 23 has been updated with features that focus on content distribution, engagement, and accessibility. According to Opera, the new update will also help users get the content they want faster than before.
The new Opera Mini browser will offer users the option to download files easier with its auto scan feature. Users can download files quickly and easily without accidentally clicking the unwanted pop-up ads. Basically when a user visits social media or video sites, the browser will automatically scan for direct download links under the Extreme Mode. The downloadable content will be directly available from a drop-down menu on the top rather than scrolling through the web page. Currently the auto scan feature works on Facebook, Pagalworld, Tubidy, DJPunjab and more are being added.
opera-mini-update (2)
The new Opera Mini app will also feature a built-in newsfeed feature. According to the company, it will be a more personal newsreader which will learn about people’s reading habits to provide more relevant content.
Other features on the new Opera Mini browser include compression of saved pages where the size of a page one saves will become as little as 10 percent of their original size, support for video boost when using Extreme mode which reduces up to 50 percent of data consumption when watching video and full-menu Facebook Android notification bar users get access to notifications without the need to open another app.
opera-mini-update (1)
“Mobile browsers are becoming the gateway to the internet users in India, and most of the users consume content on the small screen these days while on the move. There are challenges regarding limited bandwidth availability, content distribution and accessibility, ” says Nuno Sitima, Executive Vice President of the mobile business unit at Opera Software. “Opera has stepped up the game for browsers, introducing novel features such as video boost and built-in ad-blocker. With these handy new features, we want our users get the most out of the web.”
Publish date: March 24, 2017 12:28 pm| Modified date: March 24, 2017 12:28 pm

Saturday, January 14, 2017

Meet Opera Neon, the experimental browser that might replace your desktop

Meet Opera Neon, the experimental browser that might replace your desktop

By 
Opera Neon is an alternative, experimental browser from Opera that wants to give us a glimpse into the future of computing.
It’s the design of Opera Neon that instantly catches your attention. While opening a traditional browser like Google Chrome or even regular Opera feels like you’ve opened an app, Opera Neon feels like a new interface for interacting with your computer. The only comparison that springs to mind is switching to, say, Unity Desktop after spending years in Gnome Desktop.
Neon 1
It feels like a desktop.
The whole UI is all bubbles. Speed dial is replaced with a handful of bubbles, each one representing a web page. New tabs show up as bubbles on the side of the browser and visual elements like progress bars are also bubbles.
Neon’s UI feels great. It’s visually pleasing and very distinct, especially after you come from the utilitarian efficiency of Chrome. I like the fact that browser tabs pop on the side rather than on top, it’s actually a more convenient place to put them, and in-browser split-screen modes, pop-out video playback and other such features are all nice to use.
Neon 2
My favourite feature is the snap-to-gallery feature. You tap the snap button on the browser, drag a box around whatever it is you want to capture and voila! A snapshot of the area you selected is automatically dumped in an easy-to-access tab. Better still, the image will also link to the source site, so a snapshot of a YouTube video will link to that YouTube video, for example.
Neon 3
I noticed that Neon took my desktop wallpaper as the browser background, this, and the overall design, add to the effect that you’re using a new desktop UI than something that is just a browser.
The large icons also mean that the UI is touch-friendly, so there’s no need to switch between desktop and tablet mode on devices like 2-in-1s.
All things considered, Neon is a great demo of what a browser can be.
It’s not as powerful as something like Chrome or Vivaldi (no extensions, tab and file management issues, etc.), but it’s a very pleasant, refreshing browser that I can see myself using while I laze about on the couch.
You can download Opera Neon here. Let us know what you think in the comments section below!

Tuesday, October 11, 2016

Google Chrome 55 will consume less RAM, promises Google

Google Chrome 55 will consume less RAM, promises Google

By 
Google Chrome is a notorious resource hog. It’s been known to gobble up all the free RAM on your system and drain your battery at an alarming rate. Come December, and all this is set to change.
Chrome 55, which debuts on 6 December, will reportedly use an updated JavaScript engine,reports CNET. Google says that the updated engine uses much less RAM and that the benefits can amount to 50 percent more free RAM.
As far as most of the web-browsing world is concerned, however, they’d rather be using Chrome than any other browser. There are those who’ll stick to the default browser, be it Safari or Internet Explorer (IE) or even Edge, but those folk are unlikely to care about things like RAM consumption and battery life.
On a side note, using Safari on macOS or Edge on Windows 10 will give you better battery life and consume less RAM on that platform than Chrome. In fact, Opera goes so far as to claim that their browser, in battery saver mode, can knock the socks of any other browser in the battery life department.
That said, Chrome’s newfound frugality should have little impact on your battery life or browsing performance. If you’re on a device that’s struggling for

Tuesday, October 4, 2016

Top 10 Internet tips and tricks


Internet browsers

























Take advantage of tabbed browsing

Take full advantage of tabbed browsing on all Internet browsers. While reading an article or browsing a website, you may come across a link that interests you. Any link to another page can be opened in a new tab so it does not interrupt your reading. To perform this action, hold down the Ctrl key and left-click the link. If you have a mouse with a wheel, click the link by depressing the wheel instead of rolling it. Either of the methods opens a link in a new window.
Tip: To open an new blank tab, press Ctrl + T at the same time.

You don't need the http:// portion of a web page

When entering an Internet address you do not need to type http:// or even www. in the address. For example, if you wanted to visit Computer Hope you could just type computerhope.com and press enter. To make things even quicker, if you are visiting a .com address you can type computerhope and then press Ctrl + Enter to type out the full http://www.computerhope.com address.

Quickly move between the fields of a web page

If you are filling out an online form, e-mail, or other text field you can quickly move between each of the fields by pressing the Tab key or Shift +
Related Posts Plugin for WordPress, Blogger...