Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
unix entropy source can be used for keystroke timing attacks Aug 14 2003 11:03PM
Michal Zalewski (lcamtuf ghettot org)

Another bizarre vulnerability, for your amusement...

Several unix systems systems provide a secure entropy source maintained by
collecting certain information that is supposed to be practically
unpredictable (such as interrupt timings, keyboard scancodes or device
request times), then running it t...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus