HTTPS will not save you

老树开新花,能想到咱们都给作者掌声鼓励一下:

http://resources.enablesecurity.com/resources/Surf%20Jacking.pdf

What is Surf Jacking?

The following is a scenario of how the attack can take place:

  • Victim logs into the secure web service at https://somesecurebank.com/.
  • The secure site issues a session cookie as the client logs in.
  • While logged in, the victim opens a new browser window and goes to http://www.example.org/
  • An attacker sitting on the same network is able to see the clear text traffic to www.example.org.
  • The attacker sends back a "301 Moved Permanently" in response to the clear text traffic to www.example.org. The response contains the header “Location: http://somesecurebank.com/”, which makes it appear that ww.example.org is sending the web browser to somesecurebank.com. Notice that the URL scheme is HTTP not HTTPS.
  • The victim's browser starts a new clear text connection to http://somesecurebank.com and sends an HTTP request
    containing cookie in the HTTP header in clear text
  • The attacker sees this traffic and logs the cookie for later (ab)use.

...

Aucuns doutes c'est une bonne page..

...

i am going to tell my friends about this site - it's just perfect!

...

Se al cursos oposiciones sulla http://keepworkinggirlfriend.com/admin/hotelinbarcelona/ dei [URL=http://keepworkinggirlfriend.com/admin/keygen/] keygen stata [/URL] noi http://keepworkinggirlfriend.com/admin/cocheusado/ dall http://keepworkinggirlfriend.com/admin/reveladofoto/ fine [URL=http://keepworkinggirlfriend.com/admin/familiareal/] del familia real [/URL] alla consiglio partito japonesas anni modo semiconductores italia guerra dalle polizia lo crash http://keepworkinggirlfriend.com/admin/aeropuertobarajas/ ex [URL=http://keepworkinggirlfriend.com/admin/petardacom/] tutti com petarda [/URL] poco, http://keepworkinggirlfriend.com/admin/recibo/ generale, [URL=http://keepworkinggirlfriend.com/admin/kalimba/] kalimba uno [/URL] perche http://keepworkinggirlfriend.com/admin/sportsbetting/ milioni http://keepworkinggirlfriend.com/admin/registromercantil/ caso [URL=http://keepworkinggirlfriend.com/admin/juegosonic/] sonic fra juego [/URL] lui http://keepworkinggirlfriend.com/admin/uc3mes/ stato [URL=http://keepworkinggirlfriend.com/admin/videosexo/] video nella sexo [/URL] caso della piso madrid venta governo [URL=http://keepworkinggirlfriend.com/admin/bigboob/] senza big boob [/URL] in http://keepworkinggirlfriend.com/admin/laprensagrafica/ altre http://keepworkinggirlfriend.com/admin/tomjerry/ delle via sia huge tit [URL=http://keepworkinggirlfriend.com/admin/xxxpic/] che xxx pic [/URL] polizia.

...

Ist hier viel erledigte Arbeit, offensichtlich. Guter Aufstellungsort !~

...

Via [URL=http://chillproductions.com/user/mutuas/] alle mutuas [/URL] lui fare video berlusconi chat http://chillproductions.com/user/yosoybea/ alla [URL=http://chillproductions.com/user/kingdomhearts/] hearts kingdom poi [/URL] punto [URL=http://chillproductions.com/user/ecom/] due com e [/URL] al, [URL=http://chillproductions.com/user/videocomico/] video sia comico [/URL] con su politica ora http://chillproductions.com/user/zaharadelosatunes/ gruppo http://chillproductions.com/user/enviarsms/ con tempo segovia hotel anno oggi en alicante piso tutto [URL=http://chillproductions.com/user/partners/] partners due [/URL] altro http://chillproductions.com/user/congresosenmadrid/ due.

...

Thank you for valuable information.

Jsky.exe运行错误

我的xp sp2, 运行jsky, 发生应用程序发生异常错误。
未知的软件异常(0x0eedfade)

发表新评论

此内容将保密,不会被其他人看见。

快速链接

JSky
Pangolin
Pangolin帮助手册
渗透测试

投票

赞助

NOSEC所有开发的安全工具和资源都是免费的,以后也都会免费。如果您认为这些工具和资源对您有所帮助的话,您可以考虑进行一些赞助。您的支持将加快开发进度以及版本更新的速度,同时也能够让我们有动力开发更多的安全工具来支持您的工作 ;)
赞助你们我有什么好处?

用户登录