OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Full-disclosure] DLL hijacking with Autorun on a USB drive

From: coderman (codermangmail.com)
Date: Tue Aug 31 2010 - 18:26:20 CDT


On Tue, Aug 31, 2010 at 4:14 PM, Dan Kaminsky <dandoxpara.com> wrote:
>...
> It's not that they can't. It's that they don't, and we have huge
> amounts of data confirming this. Have you never been to a Moxie
> Marlinspike talk?  His success rates on SSL Stripping a tor node were
> 100%. 100%!!!

this was days into his experiment, however, and those with clue were
scared away from his exit pretty quick. i believe Moxie mentioned this
as a shortcoming in his presentation - it would have been nice to
collect stats from the get go. then he might have shown only a 99.72%
success rate.

(some people *still* use IE over Tor, which is absolute insanity)

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/