Full Disclosure mailing list archives

Re: DLL hijacking with Autorun on a USB drive


From: coderman <coderman () gmail com>
Date: Tue, 31 Aug 2010 16:26:20 -0700

On Tue, Aug 31, 2010 at 4:14 PM, Dan Kaminsky <dan () doxpara com> wrote:
...
It's not that they can't. It's that they don't, and we have huge
amounts of data confirming this. Have you never been to a Moxie
Marlinspike talk?  His success rates on SSL Stripping a tor node were
100%. 100%!!!

this was days into his experiment, however, and those with clue were
scared away from his exit pretty quick. i believe Moxie mentioned this
as a shortcoming in his presentation - it would have been nice to
collect stats from the get go. then he might have shown only a 99.72%
success rate.

(some people *still* use IE over Tor, which is absolute insanity)

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: