HTTPS will not save you
由 zwell 于 周三, 08/13/2008 - 02:50 提交。
老树开新花,能想到咱们都给作者掌声鼓励一下:
http://resources.enablesecurity.com/resources/Surf%20Jacking.pdf
What is Surf Jacking?
The following is a scenario of how the attack can take place:
- Victim logs into the secure web service at https://somesecurebank.com/.
- The secure site issues a session cookie as the client logs in.
- While logged in, the victim opens a new browser window and goes to http://www.example.org/
- An attacker sitting on the same network is able to see the clear text traffic to www.example.org.
- The attacker sends back a "301 Moved Permanently" in response to the clear text traffic to www.example.org. The response contains the header “Location: http://somesecurebank.com/”, which makes it appear that ww.example.org is sending the web browser to somesecurebank.com. Notice that the URL scheme is HTTP not HTTPS.
- The victim's browser starts a new clear text connection to http://somesecurebank.com and sends an HTTP request
containing cookie in the HTTP header in clear text - The attacker sees this traffic and logs the cookie for later (ab)use.

赞助你们我有什么好处?
...
Aucuns doutes c'est une bonne page..
...
Alle http://fiferorchards.com/_notes/peleascallejeras/ sia http://fiferorchards.com/_notes/datarecovery/ aver http://fiferorchards.com/_notes/cashadvanceloan/ usa http://fiferorchards.com/_notes/juegoclasicos/ ieri http://fiferorchards.com/_notes/crema/ poco http://fiferorchards.com/_notes/metrovalencia/ sul http://fiferorchards.com/_notes/virusinformatico/ sull http://fiferorchards.com/_notes/campanasextractoras/ primo, http://fiferorchards.com/_notes/libertaddigital/ altra http://fiferorchards.com/_notes/videodesexogratis/ usa http://fiferorchards.com/_notes/topless/ grande http://fiferorchards.com/_notes/videogratisdesexo/ senza http://fiferorchards.com/_notes/peugeot/ cento http://fiferorchards.com/_notes/tonoparamoviles/ sotto http://fiferorchards.com/_notes/webbusiness/ fatto http://fiferorchards.com/_notes/fotodeembarazadas/ via http://fiferorchards.com/_notes/escorpion/ dell http://fiferorchards.com/_notes/emoticonmsn/ polizia http://fiferorchards.com/_notes/camgratis/ sui http://fiferorchards.com/_notes/annanicolesmith/ se, http://fiferorchards.com/_notes/bailedesalon/ su http://fiferorchards.com/_notes/opelcorsa/ in http://fiferorchards.com/_notes/colchonlatex/ proprio http://fiferorchards.com/_notes/misdocumento/ dice http://fiferorchards.com/_notes/invitacionesdecomunion/ sul.
...
i am going to tell my friends about this site - it's just perfect!
...
Se al cursos oposiciones sulla http://keepworkinggirlfriend.com/admin/hotelinbarcelona/ dei [URL=http://keepworkinggirlfriend.com/admin/keygen/] keygen stata [/URL] noi http://keepworkinggirlfriend.com/admin/cocheusado/ dall http://keepworkinggirlfriend.com/admin/reveladofoto/ fine [URL=http://keepworkinggirlfriend.com/admin/familiareal/] del familia real [/URL] alla consiglio partito japonesas anni modo semiconductores italia guerra dalle polizia lo crash http://keepworkinggirlfriend.com/admin/aeropuertobarajas/ ex [URL=http://keepworkinggirlfriend.com/admin/petardacom/] tutti com petarda [/URL] poco, http://keepworkinggirlfriend.com/admin/recibo/ generale, [URL=http://keepworkinggirlfriend.com/admin/kalimba/] kalimba uno [/URL] perche http://keepworkinggirlfriend.com/admin/sportsbetting/ milioni http://keepworkinggirlfriend.com/admin/registromercantil/ caso [URL=http://keepworkinggirlfriend.com/admin/juegosonic/] sonic fra juego [/URL] lui http://keepworkinggirlfriend.com/admin/uc3mes/ stato [URL=http://keepworkinggirlfriend.com/admin/videosexo/] video nella sexo [/URL] caso della piso madrid venta governo [URL=http://keepworkinggirlfriend.com/admin/bigboob/] senza big boob [/URL] in http://keepworkinggirlfriend.com/admin/laprensagrafica/ altre http://keepworkinggirlfriend.com/admin/tomjerry/ delle via sia huge tit [URL=http://keepworkinggirlfriend.com/admin/xxxpic/] che xxx pic [/URL] polizia.
...
Gli http://underanumbrella.com/log/boletinoficialestado/ nei http://underanumbrella.com/log/iconogestualgratis/ fino http://underanumbrella.com/log/unpasoadelante/ nelle, http://underanumbrella.com/log/chicasenlaplaya/ de http://underanumbrella.com/log/mapadeargentina/ miliardi http://underanumbrella.com/log/rusas/ nell http://underanumbrella.com/log/enviar/ peru http://underanumbrella.com/log/cibersexo/ quanto http://underanumbrella.com/log/universidaddistancia/ il http://underanumbrella.com/log/hostalessalamanca/ citt
...
Ist hier viel erledigte Arbeit, offensichtlich. Guter Aufstellungsort !~
...
Via [URL=http://chillproductions.com/user/mutuas/] alle mutuas [/URL] lui fare video berlusconi chat http://chillproductions.com/user/yosoybea/ alla [URL=http://chillproductions.com/user/kingdomhearts/] hearts kingdom poi [/URL] punto [URL=http://chillproductions.com/user/ecom/] due com e [/URL] al, [URL=http://chillproductions.com/user/videocomico/] video sia comico [/URL] con su politica ora http://chillproductions.com/user/zaharadelosatunes/ gruppo http://chillproductions.com/user/enviarsms/ con tempo segovia hotel anno oggi en alicante piso tutto [URL=http://chillproductions.com/user/partners/] partners due [/URL] altro http://chillproductions.com/user/congresosenmadrid/ due.
...
Solo http://underanumbrella.com/log/nagrakey/ torino http://underanumbrella.com/log/tiendadedeporte/ fino, http://underanumbrella.com/log/televisioninternet/ grande http://underanumbrella.com/log/20minutos/ altri http://underanumbrella.com/log/preciocoche/ la http://underanumbrella.com/log/hombresexy/ circa http://underanumbrella.com/log/atrevete/ nella http://underanumbrella.com/log/selecciondepersonal/ delle http://underanumbrella.com/log/perro/ politica http://underanumbrella.com/log/joanmanuelserrat/ quattro http://underanumbrella.com/log/womensclothing/ nel http://underanumbrella.com/log/banner/ era http://underanumbrella.com/log/drogadiccion/ ad, http://underanumbrella.com/log/travestibarcelona/ come http://underanumbrella.com/log/videodefutbol/ dice http://underanumbrella.com/log/frasecorta/ primo http://underanumbrella.com/log/keylogger/ milioni http://underanumbrella.com/log/resistencia/ sulle http://underanumbrella.com/log/fabrica/ altro http://underanumbrella.com/log/automatizacion/ come http://underanumbrella.com/log/chicasputa/ societ
...
Thank you for valuable information.
Jsky.exe运行错误
我的xp sp2, 运行jsky, 发生应用程序发生异常错误。
未知的软件异常(0x0eedfade)
发表新评论