Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Beware 'Brown Orifice'
Kevin Poulsen, SecurityFocus 2000-08-07

The latest in backdoor programs comes in through your web browser.

Comments Mode:
What ports does Brown orifice use, how can it be detected? 2000-08-08
Sean Boran (2 replies)
What ports does Brown orifice use, how can it be detected? 2000-08-08
morphon (at) yahoo (dot) com [email concealed]
What ports does Brown orifice use, how can it be detected? 2000-08-08
Henri Torgemane <henri_torgemane (at) yahoo (dot) com [email concealed]>
Re: Beware 'Brown Orifice' 2000-08-09
Lori Carrig (2 replies)
Re: Beware 'Brown Orifice' 2000-08-09
Bruce
Re: Beware 'Brown Orifice' 2000-08-11
netapi (2 replies)
IP not snatchable from IE? well sorta. 2000-08-11
henri torgemane
a small test on IE5 with an applet doing a

System.out.println(InetAddress.getLocalHost());

generate a security exception, which is good.

What is not so good is the text of that security exception:

com.ms.security.SecurityExceptionEx[Test.init]: cannot access "hostname.goes.here"

kinda defeat the purpose of blocking the method in the first place.

(although you only get the hostname, which might not be resolvable to an IP from an outside DNS.. )

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/70/2999#2999
Re: Beware 'Brown Orifice' 2000-08-17
Orca_sniff







 

Privacy Statement
Copyright 2009, SecurityFocus