Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Unexpected Attack Vectors
Scott Granneman, 2005-02-09

A new round of attacks and phishing attempts use some unexpected attack vectors that we should have been paying attention to, but weren't.

Comments Mode:
Unexpected Attack Vectors 2005-02-10
Phil
An entertaining and informative article.

I hope Opera sees the light....

[ more ]  [ reply ]
Unexpected Attack Vectors 2005-02-10
Anonymous
Old news, in new article.

Security is a proces.

In this proces you don't take counter measures to prevent some small attack vectors, but you deny anythink you don't want.

If you allow your users to download things, if you allow your users to open ssl tunnels, if you allow your users to send...

[ more ]  [ reply ]
Unexpected Attack Vectors 2005-02-10
Anonymous
Don't forget the ability to bypass AV, IDS and IPS systems by using RFC 2397 encoded images. This is much more critical than sending archives as it doesn't require any user interaction.
...

[ more ]  [ reply ]
Beware! Suggested fix doesn't work in Firefox 1.0 2005-02-10
Anonymous (1 replies)

A bug in Firefox 1.0 prevents the suggested fix (editing file user.js) from being effective. A better fix for Firefox 1.0 consists in editing the compreg.dat file.

Reference: https://bugzilla.mozilla.org/show_bug.cgi?id=279099#c47

...

[ more ]  [ reply ]
Beware! Suggested fix doesn't work in Firefox 1.0 2005-02-11
Anonymous
Same story with Mozilla 1.7.5. Editing compreg.dat fixes it, but of course this also means I can no longer visit exciting sites like
http://www.omvärlden.nu. ...

[ more ]  [ reply ]
As predicted 2005-02-10
Barrie Dempster (1 replies)
I predicted this and it sparked a fair discussion on FD, with one vendor chiming in that they make take notice.

it was only a matter of time

http://zeedo.blogspot.com/2005/02/multiple-av-vendors-ignori
ng-targz.html...

[ more ]  [ reply ]
As predicted 2005-02-16
Anonymous
I thought of this long ago and simply deny them. ...

[ more ]  [ reply ]
Unexpected Attack Vectors 2009-04-21
Anonymous
post some details regading virus affected url 's and example programs also...........

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus