WebApp Sec mailing list archives

Using Java in anti DNS-pinning attacks (Firefox and Opera)


From: "Martin Johns" <martin.johns () gmail com>
Date: Sun, 4 Feb 2007 21:51:52 +0100

Hello,

Kanatoko (from jumperz.net) and I did some more work in respect to
using Java-code in anti DNS-pinning attacks. It is possible to use JDK
classes thanks to the LiveConnect feature in Firefox and Opera. If you
are interested, some details can be found in my blog
(http://shampoo.antville.org/stories/1566124/ ) and Kanatoko wrote a
PoC: http://www.jumperz.net/index.php?i=2&a=1&b=9

Best,
Martin
--
Martin Johns
http://www.martinjohns.com

-------------------------------------------------------------------------
Sponsored by: Watchfire

Today's hackers exploit web applications to expose, embarrass and even steal. Firewalls and SSL may be commonplace but recent studies indicate 3 out of 4 websites remain vulnerable to attack. Watchfire's "Addressing Challenges in Application Security" whitepaper, explains what to do and provides a guideline to improving your own application security. Download this whitepaper today!

https://www.watchfire.com/securearea/whitepapers.aspx?id=701500000008fHF
--------------------------------------------------------------------------


Current thread: