Zurück   Free To Advertise Forum >Community Center >General Discussion

General Discussion

Talk about anything from politics to t.v. shows, kids, internet news ....etc This is the place to also blow off some steam from your normal day activities. NO Affiliate Links!


If you register for free, you will be able to post threads, vote on polls and lots more. If you have problems with the registration or logging in, please contact the administrator.

Antwort
 
Themen-Optionen
  iPhone SSL Warning and Safari Phishing Beitrag #1  
Alt 08-17-2010, 05:58 AM
rhody249 rhody249 ist offline
New Marketer
 
Registriert seit: Dec 2009
Beiträge: 95
Standard iPhone SSL Warning and Safari Phishing

As some of you may have noticed, there’s a lot more going on in the SSL world and a lot more to come thanks to guys like Mike Zusman, Alex Sotirov Moxie Marlinspike and so on… Papers forthcoming, but in the mean time I thought I’d point out a pretty nasty UI issue with the iPhone, since it’s been something I’ve been meaning to post about for a while. Given the rise in mobile computing as a legitimate way to do business, I think this kind of thing is going to become more important. If an attacker can gain MITM access through a public wifi that the iPhone is using, they can intercept a page that the user normally uses and trusts somewhat, but doesn’t necessary trust with any sensitive data (like a blog or forum that they frequently visit for instance).


What you’re seeing is a 1×1 pixel iframe (doesn’t need to be visible, but it’s good for testing purposes) to https://www.bofa.com/ which uses an invalid certificate. Don’t ask me why one of the largest banks on earth can’t get their certs in order - that’s just the way it is. Anyway, let’s pretend instead of it being incredible sloppiness, it’s actually a MITM. The user is presented with a popup that in no way explains to them what the cert they are accepting is for. So their first instinct would be to accept it, because they aren’t going to be putting any sensitive information into the page anyway. The problem is that the cert stays with the browser session - so it will continue to work, when the user does eventually surf to their bank or whatever SSL page you’ve MITM’d.


Compare that to the desktop version of Safari, where it at least tells you that it’s related to www.bofa.com. Still not the greatest visual cue but it’s something. Incidentally, during this testing I messed around with some of the old tricks and found out that that Safari still suffers from the old URL obfuscation tricks of ages past.Eg: http://www.bofa.com@ha.ckers.org/.
Mit Zitat antworten
Antwort

Zurück   Free To Advertise Forum >Community Center >General Discussion

Themen-Optionen


Similar threads to iPhone SSL Warning and Safari Phishing
Thema Autor Forum Antworten Letzter Beitrag
FREE OFFER!!Effective Protection from Spam, Phishing and Dangerous Websites!
FREE OFFER!!Effective Protection from Spam, Phishing and Dangerous Websites!: FREE OFFER!! Effective Protection from Spam,...
goodday4u Products, Services & Offers 0 02-04-2010 01:55 AM
Tagua Jewelry Ginger Safari Tribal Fashion
Tagua Jewelry Ginger Safari Tribal Fashion: Tagua Jewelry Ginger Safari Tribal Fashion ...
phoenix06007 Products, Services & Offers 0 09-07-2009 05:20 AM

More threads of rhody249
Thema Datum Forum Antworten Letzter Beitrag
10 tips on how to increase your website traffic
10 tips on how to increase your website traffic: Hi friends, Here are the ten useful tips, ...
06-01-2010 General Discussion 2 12-28-2011 06:00 AM
Side Channel Attacks in SSL
Side Channel Attacks in SSL: For those of you who may not have seen it there...
08-17-2010 General Discussion 0 08-17-2010 03:00 AM
Link wheel
Link wheel: Hi friends. Today I am going to share a...
06-01-2010 General Discussion 0 06-01-2010 12:47 AM
Which will be the hottest movie in 2010??
Which will be the hottest movie in 2010??: Hi friends I just wanna know that which Hollywood...
01-31-2010 General Discussion 0 01-31-2010 11:53 PM
Online E-learning Software
Online E-learning Software: Hi, Buy Best E-Learning Software and Website...
12-22-2009 Products, Services & Offers 0 12-22-2009 07:15 AM

Other threads in forum General Discussion
Thema Datum Autor Antworten Letzter Beitrag
Let’s remember our child hood days to gather!!
Let’s remember our child hood days to gather!!: Respected All Members, Most of us all like...
01-29-2010 realistic 1 01-30-2010 01:59 AM
JAPAN Farmacias más barato cheapest drug KAMAGRA WHERE TO BUY KAMAGRA
JAPAN Farmacias más barato cheapest drug KAMAGRA WHERE TO BUY KAMAGRA: JAPAN Farmacias más barato cheapest drug KAMAGRA...
11-10-2009 AlcoriDor1 0 11-10-2009 06:48 AM
Wholesale Purses. Wholesale Designer Purses. Wholesale Replica Purses
Wholesale Purses. Wholesale Designer Purses. Wholesale Replica Purses: ENTER HERE ...
04-03-2009 frenssis 0 04-03-2009 02:31 PM
Buy Soma Cod, Soma Cod Delivery
Buy Soma Cod, Soma Cod Delivery: ENTER HERE ...
03-29-2009 frenssis 0 03-29-2009 07:03 AM


Alle Zeitangaben in WEZ -4. Es ist jetzt 05:44 AM Uhr.


Powered by vBulletin® Version 3.8.7 (Deutsch)
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
2007-2008 Free To Advertise Forum
Sedo - Domains kaufen und verkaufen das Projekt freetoadvertise.biz steht zum Verkauf Besucherstatistiken von freetoadvertise.biz etracker® Web-Controlling statt Logfile-Analyse
You are viewing iPhone SSL Warning and Safari Phishing

SEO by vBSEO 3.2.0