Home page logo

fulldisclosure logo Full Disclosure mailing list archives

Re: blocking Google Desktop
From: Michael Holstein <michael.holstein () csuohio edu>
Date: Fri, 10 Feb 2006 16:47:07 -0500

Looks like a great target for Pharming attacks. Thanks for all your data
sent to me over an SSL connection. =)

Yeah .. Google is notorious for trying to send everything into the same domain -- trying to make our lives difficult.

Right now, I'm trying snort with REACT actions based on their SSL certificate fingerprint. Preventing the key exchange would prevent the session setup.

I just need to see if that'd block Gmail as well.

Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]