I noticed if I went to Delicious' https login page via my user page (http://delicious.com/[username]) then Firefox always gave a 'there is unencrypted content included in this https page' warning, and further that if I attempted to then log in the cursor jumps back up to the user name text box from the password box a few seconds after typing in my user name, which would normally result in the password being typed into the clear text user name box my being totally oblivious to the fact the cursor had backtracked on itself. This is standard hacking I am used to. Note though if I instead login via the Delicious home portal page (Delicious) then there is no such warning from Firefox and no evidence of any malware on the login page. [Edit: This seems to have fixed itself by the next day, the login page now opens without any content errors from my user page.]
Apart from my ruling out virtually all possible opportunity for installing malware on my computer with security measures etc. otherwise, I think the above is self evident in itself that this is a MITM attack, and specifically targeted at myself? (That is the main question of this post
I don't propose to describe the install, accept to say that I have various security measures in place (firewall, VM, etc., though not the level of security a network engineer could put in place unfortunately not being one myself), however without running Tor (i.e., using an encrypted vpn alone) I have found the browser is hacked quite quickly. (With Tor I have found in the past that as Tor changes servers any browser hacks clear, though having said that my current install with Tor seems to be keeping all browser hacks out, or at least so far.)
If anyone can make any sense of the above, or maybe point me in the direction of the log files to start studying, etc. I'd be truly grateful
---------- Post updated at 01:00 AM ---------- Previous update was at 12:55 AM ----------
LOL, that last post just posted itself without my pressing the submit button, I'm not sure whether to laugh or cry!!
---------- Post updated at 11:53 AM ---------- Previous update was at 01:00 AM ----------
Firefox has a policy of essentially not notifying of mixed content encrypted pages, the about:config settings to change this: ---------- Post updated at 12:13 PM ---------- Previous update was at 11:53 AM ----------
As I said above if I don't use Tor hacking very quickly (at some point later in the day) renders the browser virtually unbearably sluggish, text entered into text boxes is also changed as I am typing, etc. However using Tor I'm now at the point where I can note suspect behaviour of specific websites, ergo!:
1) the bit.ly page that renders when using their bookmarklet to shorten a webpage being viewed is corrupted: sometimes the row displaying the shortened URL is duplicated (i.e., there are two rows for the one bookmarklet), I've had also a corruption of the 'customise | copy text' to, e.g., 'customise |'; the bookmarklet works cleanly on a fresh install for a while before exhibiting this behaviour subsequently on each use; would a https bookmarklet fix this? [Edit: Page HTML attached.]
2) http://www.infosniper.net -- I've had an episode of sorry.google.com errors from infosniper's page with the google map not rendering subsequently (closing the browser tab fixes this, could do with a https site to do the same here I think) [Edit: Page HTML attached.]
Hi Folks,
This might be a very question,but i have not been able to find the solution.
While accessing http://16.138.32.128/ in my LAN, i am able to read the index.html placed in DocumentRoot(/var/www/html).
However if i tab in https://xx.xx.xx.xx/ ,i am only able to access the default... (0 Replies)
Is firefox complaining to anyone else that this is a Reported Attack Page!? I have used this site a million times and now it feels like complaining.
Fedora Manpages: Home (5 Replies)
Here is the code I have so far
#!/bin/bash
INFOF="/tmp/mac.info"
curl --silent http://www.everymac.com/systems/apple/macbook_pro/specs/macbook-pro-core-2-duo-2.8-aluminum-17-mid-2009-unibody-specs.html "$INFOF"
I want help putting these specs into a vars
Standard Ram: value into $VAR1... (1 Reply)
hi,
i want to execute a shell script as a different user. the flow is like this.
there is a html web page from which i have to call a shell script. web server is apache. to call the shell script from html page, a perl script is required.
so the html page calls the perl script and the perl... (2 Replies)
Hi Guys,
I have recently started reciving below Error message
Failed HTTPS transfer to https://supportfiles.sun.com/curl
whenever I run
/usr/local/bin/sudo /opt/SUNWexplo/bin/explorer -P -q -v
from all Servers.
Looks like the SSL certificate as Expired.
Whenever I type... (4 Replies)