BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
RE: Windows Server 2003 Security Guide available Apr 29 2003 07:49AM
Jason Coombs (jasonc science org)
> what stops them from generating a new SHA-1 or MD5 hash?

The hash is communicated through a different channel. If somebody forges
Microsoft's announcement message or intercepts and changes it during delivery
(omnipotent MITM) then a fake hash can be planted as you suggest. However, the
omnipotent...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus