Welcome, Guest. Please login or register.
July 22, 2025, 07:03:27 AM

Login with username, password and session length

Search:     Advanced search
we're back, baby
*
Home Help Search Login Register
f13.net  |  f13.net General Forums  |  General Discussion  |  Topic: New Explot FTW: The Internet Pwns j00 0 Members and 1 Guest are viewing this topic.
Pages: [1] Go Down Print
Author Topic: New Explot FTW: The Internet Pwns j00  (Read 3264 times)
Ookii
Staff Emeritus
Posts: 2676

is actually Trippy


WWW
on: August 02, 2007, 04:03:01 PM

So basically this guy named Dan Kaminsky figured out how to turn your browser into a 'vpn concentrator', from the arcticle:

Quote
The technique originates in the browser security model, based on same-origin policy. This allows a web browser, either using JavaScript or Flash, to connect back to the same host that the content came from. If the attacker changes where the hostname is pointing to, the browser can connect there. For example, the next time you connect to attacker.com, the DNS server actually serves you a 192.168.1.1 address, allowing the webapp to connect to your internal IP.

The POC at http://www.jumperz.net/index.php?i=2&a=1&b=7 worked on my corporate network too, and apparently there is nothing you can do to stop it at the moment.

The Original Article: http://radar.oreilly.com/archives/2007/08/your_web_browse.html
More Whitepaperish: http://www.megginson.com/blogs/quoderat/2007/08/01/protecting-web-sites-and-services-from-dns-rebinding-attacks/

So basically right now if someone knows where something is in an internal network, and can get you to visit their website, you're pwned.

Ironwood
Terracotta Army
Posts: 28240


Reply #1 on: August 03, 2007, 01:01:57 AM

Scaring the fishes.

 shocked

"Mr Soft Owl has Seen Some Shit." - Sun Tzu
Oban
Terracotta Army
Posts: 4662


Reply #2 on: August 03, 2007, 01:42:11 AM

I sent this to my web devs and have yet to hear from them... never a good sign.

Palin 2012 : Let's go out with a bang!
Sky
Terracotta Army
Posts: 32117

I love my TV an' hug my TV an' call it 'George'.


Reply #3 on: August 03, 2007, 06:24:54 AM

Cool link, thanks. I sent it to the librarians who are messing themselves trying to figure out how to make everything web 2.0.

Fucking buzzword douchebags. I prefer Shut The Fuck Up 1.9.
Roac
Terracotta Army
Posts: 3338


Reply #4 on: August 03, 2007, 06:32:15 AM

I sent this to my web devs and have yet to hear from them... never a good sign.

Please wait for 15 seconds.
f1()
ERROR: Access is denied.
ERROR: http://jumperz.net/exploits/dnsp3.jsp?address=127.0.0.1
ERROR: 50


Can't get it to work.  Well, won't work for us at all anyway because all our websites require a host header, which the poc won't accept.  I tried setting up a default page on the default website for it to hit, but it can't see that either.  Then tried setting up a default on localhost, and it's not getting even that.  Firefox was more interesting, but still didn't work:


ERROR: uncaught exception: Security Error: Content at http://jumperz.net/exploits/dnsp3.jsp?address=127.0.0.1 may not load data from http://www.jumperz.net/index.php.

-Roac
King of Ravens

"Young people who pretend to be wise to the ways of the world are mostly just cynics. Cynicism masquerades as wisdom, but it is the farthest thing from it. Because cynics don't learn anything. Because cynicism is a self-imposed blindness, a rejection of the world because we are afraid it will hurt us or disappoint us." -SC
Trippy
Administrator
Posts: 23657


Reply #5 on: August 03, 2007, 06:36:28 AM

This isn't a "Web 2.0" specific thing.
Sky
Terracotta Army
Posts: 32117

I love my TV an' hug my TV an' call it 'George'.


Reply #6 on: August 03, 2007, 07:09:03 AM

This isn't a "Web 2.0" specific thing.

I know but he does mention the vulnerability and his trepidition of the security of Web 2.0. If he's worried, I'm worried :)
bhodi
Moderator
Posts: 6817

No lie.


Reply #7 on: August 03, 2007, 08:08:35 AM

that is slick.
Trippy
Administrator
Posts: 23657


Reply #8 on: August 03, 2007, 04:52:08 PM

BTW this security flaw is much more worrisome:

http://www.tgdaily.com/content/view/33207/108/
bhodi
Moderator
Posts: 6817

No lie.


Reply #9 on: August 04, 2007, 08:31:03 AM

That's not a new flaw, it's a one-click tool that someone put together to exploit it. If you've got unencrypted traffing going over the air, you should expect to get your cookies stolen.
Oban
Terracotta Army
Posts: 4662


Reply #10 on: August 04, 2007, 08:41:59 AM

BTW this security flaw is much more worrisome:

http://www.tgdaily.com/content/view/33207/108/


Why in god's name would you use webmail without a secure connection?

Download better gmail if you use firefox.


Palin 2012 : Let's go out with a bang!
Trippy
Administrator
Posts: 23657


Reply #11 on: August 04, 2007, 02:09:44 PM

That's not a new flaw, it's a one-click tool that someone put together to exploit it. If you've got unencrypted traffing going over the air, you should expect to get your cookies stolen.
I didn't say that was a new flaw.
Sky
Terracotta Army
Posts: 32117

I love my TV an' hug my TV an' call it 'George'.


Reply #12 on: August 06, 2007, 06:13:44 AM

If you've got unencrypted traffing going over the air, you should expect to get your cookies stolen.
I'm trying to get my father to understand this. I think my next bit of advice for him is to sell his computer. He;s somehow broken every firewall known to man and doesn't use them anymore because they 'break his computer'. He also claims to have spent hours on the phone with every incident. Poor customer service, I never know what the hell he's talking about and I share half his DNA.

If I were a hacker, I'd move to Florida. Lots of retirement accounts and dipshit old people accessing them through wireless connections in the park.
Furiously
Terracotta Army
Posts: 7199


WWW
Reply #13 on: August 06, 2007, 08:45:22 PM

I suppose. But isn't it like taking candy from a baby?

Sky
Terracotta Army
Posts: 32117

I love my TV an' hug my TV an' call it 'George'.


Reply #14 on: August 07, 2007, 06:21:30 AM

Candy is tasty.
Pages: [1] Go Up Print 
f13.net  |  f13.net General Forums  |  General Discussion  |  Topic: New Explot FTW: The Internet Pwns j00  
Jump to:  

Powered by SMF 1.1.10 | SMF © 2006-2009, Simple Machines LLC