BugTraq
Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 09 2004 06:24PM
Disclosure From OSSI (disclosure ossecurity ca) (4 replies)
RE: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 09 2004 10:42PM
Oliver Lavery (olavery pivx com)
RE: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 09 2004 10:01PM
David Schwartz (davids webmaster com) (1 replies)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 10 2004 03:51AM
Darren Reed (avalon caligula anu edu au) (1 replies)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 10 2004 09:10PM
der Mouse (mouse Rodents Montreal QC CA) (3 replies)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 11 2004 06:11AM
Darren Reed (avalon caligula anu edu au) (1 replies)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 11 2004 07:07AM
der Mouse (mouse Rodents Montreal QC CA) (1 replies)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 11 2004 08:44AM
Darren Reed (avalon caligula anu edu au) (1 replies)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 11 2004 09:03AM
der Mouse (mouse Rodents Montreal QC CA)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 11 2004 04:04AM
Glynn Clements (glynn clements virgin net)

der Mouse wrote:

> > Signed applications and signed DLLs and signed drivers [...] coming
> > to a Unix near you SOONER rather than later.
>
> > Or is that the kind of thing you disable upon installation because it
> > gets in the way of you being able to install whatever "you" want ?
>
> Depends. Does it include the tools necessary to sign my own code?
>
> If not, yes, I will disable it, to the point of running a different OS
> if necessary.
>
> If so, what's to stop a malware creator from using those same tools to
> sign the attack vector?

You don't have to store the signing key on every host which needs to
run the signed binaries.

--
Glynn Clements <glynn.clements (at) virgin (dot) net [email concealed]>

[ reply ]
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 11 2004 12:28AM
John D. Hardin (jhardin impsec org) (1 replies)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 11 2004 04:56AM
der Mouse (mouse Rodents Montreal QC CA)
RE: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 09 2004 07:31PM
Ward Taylor (rfdhomer windyplains com) (2 replies)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 10 2004 04:40PM
Nexus (nexus patrol i-way co uk)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 10 2004 10:31AM
Peter Pentchev (roam ringlet net)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 09 2004 07:20PM
Seth Arnold (sarnold wirex com)


 

Privacy Statement
Copyright 2010, SecurityFocus