Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Mother, May I?
Mark Rasch, 2008-01-23

"Mommy, can I have a cookie?"

Comments Mode:
Thanks Mark 2008-01-23
Andy S.
Mother, May I? 2008-01-23
Anonymous (1 replies)
Re: Mother, May I? 2008-01-24
Mark D. Rasch
You're overlooking some issues. 2008-01-23
Anonymous (2 replies)
Re: You're overlooking some issues. 2008-01-24
Mark D. Rasch
Mother, May I? 2008-01-23
Erik N
OS utilities and public "keys" 2008-01-23
Ole Juul (1 replies)
Re: OS utilities and public "keys" 2008-01-28
Mark D. Rasch (1 replies)
Be careful what you ask for 2008-01-23
overshoot
Mother, May I? 2008-01-24
Thomas Downing (1 replies)
Internet as Commons 2008-01-28
Mark D. Rasch (1 replies)
Re: Internet as Commons 2008-01-29
Jon Hash (1 replies)
Re: Re: Internet as Commons 2008-02-01
Mark D. Rasch
Mother, May I? 2008-01-24
stacy
Not much of a cheese shop, is it? 2008-01-24
Mitch Smith (2 replies)
Re: Not much of a cheese shop, is it? 2008-01-28
Mark D. Rasch (1 replies)
Mother, May I? 2008-01-27
Anonymous (1 replies)
Re: Mother, May I? 2008-02-01
Mark D. Rasch
Mother, May I browse your public server? 2008-01-28
Anonymous (1 replies)
It's Like a Phone Book 2008-01-30
danielc
Mother, May I? - WPAD hack appears to be legal 2008-02-01
Bertman
As a grey hat, I might set my PC up as a WPAD (Windows Proxy Auto Detect) server. I might also tell any PC that wants to use my WPAD service to use my PC as a Proxy. I also might be sniffing everything on my PC that is acting as a Proxy for passwords. I might do this while at a Hotel or Coffee Shop.
I have not done anything to trespass on those PC's that fall into my trap except offer the trap. Their PC's automatically connected to me. Even though I am stealing their passwords, I did not initiate the connection.
Acording to the law, I am not tresspassing or hacking.
My username is thebertman. My password is 123456.
You have just been given a username and password in just the same way that my WPAD hack works.

Hacking your neighbors computer; Priceless.



[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/463/34907#34907
Mother, May I? 2008-02-07
Victor (1 replies)
Re: Mother, May I? 2008-02-07
Mark D. Rasch







 

Privacy Statement
Copyright 2007, SecurityFocus