Author Topic: SpoofStick For IE and FireFox  (Read 4272 times)

0 Members and 1 Guest are viewing this topic.

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48551
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
SpoofStick For IE and FireFox
« on: July 31, 2004, 04:54:56 AM »
What is SpoofStick?
SpoofStick is a simple browser extension that helps users detect spoofed (fake) websites. A spoofed website is typically made to look like a well known, branded site (like ebay.com or citibank.com) with a slightly different or confusing URL.
Get all the info and the program at the following URL:
http://www.corestreet.com/spoofstick/
Hope it helps. :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re:SpoofStick For IE and FireFox
« Reply #1 on: July 31, 2004, 01:13:48 PM »
I have it on firefox 0.9.2 and it doesn't fill me with confidence as it is easy to spoof the SpoofStick.

Yes it trys to identify the origin of the true website, but I found a simple exploit of SpoofStick totally invalidating this check.

I regularly visit a website, using a URL domain redirect. I type the friendly short domainname.com and it redirects you to thenotsofriendlyllongdomainname.com website, directory and page.html, etc.

How? the redirect can use frames as the redirect so the website opens inside a frame that appears to be the domain that you typed but it has been redirected. This in hosting terms is known as URL masking and negates SpoofStick.

When you enter a domain check the status bar at the bottom left of the browser window and you can see the path to the true website, where it is downloading images and web pages, etc.

SpoofStick is useful, just don't think it is 100% and carry out the above check when visiting websites from webpage or email links.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48551
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re:SpoofStick For IE and FireFox
« Reply #2 on: July 31, 2004, 01:53:20 PM »
Thanks DavidR
For your full explanation.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:SpoofStick For IE and FireFox
« Reply #3 on: July 31, 2004, 02:12:21 PM »
Can one of you tell me the entries this application creates in HijackThis so I can add it to the database? Thanks in advance!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re:SpoofStick For IE and FireFox
« Reply #4 on: July 31, 2004, 05:54:21 PM »
Hi Artras,

Using Firefox with spoofstick as an extension, I can't see anything in my very small hijackthis.log.

I can't see any other extensions I'm using in firefox either.

Don't know if this would be different for IE of IE base browsers.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security