Section 4.9. Browsers and Obfuscation


4.9. Browsers and Obfuscation

The variation in behavior between browsers when given some of these obfuscated URLs is frustrating. On the one hand, it shows that the developers of these tools are aware of the problem and are doing something about it. But on the other, they are building browsers that do not implement the accepted specification for URLs. While their design choices may help solve an immediate problem, they will also break any legitimate use of these features.

It is also clear, from the differences in behavior, that each development team is going its own way rather than working toward a common goal. On top of this, we are now seeing a plethora of add-on toolbars, notably for Internet Explorer, which can alert users to some forms of obfuscation. Here are three examples of those:

  • http://toolbar.netcraft.com/

  • http://www.earthlink.net/home/software/toolbar/

  • http://pages.ebay.com/ebay/toolbar/

What we need is a revision of the URL specification combined with a coordinated effort among browser developers to implement that standard. We will undoubtedly lose a few features from the current specification, which will upset some people, but it would make life quite a bit harder for the scammers.



Internet Forensics
Internet Forensics
ISBN: 059610006X
EAN: 2147483647
Year: 2003
Pages: 121

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net