Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer
From: Glynn Clements <glynn.clements () virgin net>
Date: Wed, 11 Feb 2004 04:04:54 +0000


der Mouse wrote:

Signed applications and signed DLLs and signed drivers [...] coming
to a Unix near you SOONER rather than later.

Or is that the kind of thing you disable upon installation because it
gets in the way of you being able to install whatever "you" want ?

Depends.  Does it include the tools necessary to sign my own code?

If not, yes, I will disable it, to the point of running a different OS
if necessary.

If so, what's to stop a malware creator from using those same tools to
sign the attack vector?

You don't have to store the signing key on every host which needs to
run the signed binaries.

-- 
Glynn Clements <glynn.clements () virgin net>


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]