Sponsored Content
Special Forums Cybersecurity https MITM attack via user page Post 302527646 by GSO on Saturday 4th of June 2011 04:43:13 AM
Old 06-04-2011
I'm taking the opportunity to make a quick test post (experimenting with browsers - I am always without fail hacked on this page!) while bringing this log up to date. I've taken the problem over to a thread on the Fedora SELInux forum which can be found here:

mouse pointer stuck in browser sandbox window

I also moved from SL6 over to Fedora 15 to try a current browser version out (SL6 is still using FF 3.X releases). The same bugs result though.

In a nutshell, with an install that should not have (at least in theory) been breached by an attacker gaining direct access to the keyboard, hackers can still hack the browser (running in a SELInux sandbox) -- but they don't seem to be able to hack the webpages so the encrypted VPN connection seems to be holding out - it is hacks like locking the mouse in the sandbox window, and crashing flash, that are getting through (I am fairly well sure at this stage that these are hacks).

Last edited by GSO; 06-19-2011 at 09:31 AM..
 

5 More Discussions You Might Find Interesting

1. Web Development

HTTPS-Home Page issue.

Hi Folks, This might be a very question,but i have not been able to find the solution. While accessing http://16.138.32.128/ in my LAN, i am able to read the index.html placed in DocumentRoot(/var/www/html). However if i tab in https://xx.xx.xx.xx/ ,i am only able to access the default... (0 Replies)
Discussion started by: Hari_Ganesh
0 Replies

2. What is on Your Mind?

Fedora Man Pages Reported Attack Page?

Is firefox complaining to anyone else that this is a Reported Attack Page!? I have used this site a million times and now it feels like complaining. Fedora Manpages: Home (5 Replies)
Discussion started by: cokedude
5 Replies

3. Shell Programming and Scripting

help pulling ${VARS} out of a web page user curl

Here is the code I have so far #!/bin/bash INFOF="/tmp/mac.info" curl --silent http://www.everymac.com/systems/apple/macbook_pro/specs/macbook-pro-core-2-duo-2.8-aluminum-17-mid-2009-unibody-specs.html "$INFOF" I want help putting these specs into a vars Standard Ram: value into $VAR1... (1 Reply)
Discussion started by: briandanielz
1 Replies

4. UNIX for Dummies Questions & Answers

How to switch the user before executing a shell script from web page??

hi, i want to execute a shell script as a different user. the flow is like this. there is a html web page from which i have to call a shell script. web server is apache. to call the shell script from html page, a perl script is required. so the html page calls the perl script and the perl... (2 Replies)
Discussion started by: Little
2 Replies

5. Solaris

Need suggestion:- Failed HTTPS transfer to https://supportfiles.sun.com/curl

Hi Guys, I have recently started reciving below Error message Failed HTTPS transfer to https://supportfiles.sun.com/curl whenever I run /usr/local/bin/sudo /opt/SUNWexplo/bin/explorer -P -q -v from all Servers. Looks like the SSL certificate as Expired. Whenever I type... (4 Replies)
Discussion started by: manalisharmabe
4 Replies
gss_delete_sec_context(3)				     Library Functions Manual					 gss_delete_sec_context(3)

NAME
gss_delete_sec_context() - delete a security context SYNOPSIS
DESCRIPTION
The routine deletes a security context. It also deletes the local data structures associated with the security context. When it deletes the context, the routine can generate a token. The application passes the token to the context acceptor. The context acceptor then passes the token to the routine, telling it to delete the context and all associated local data structures. When the context is deleted, the applications cannot use the context_handle parameter for additional security services. Input Parameters context_handle Specifies the context handle for the context to delete. Output Parameters minor_status Returns a status code from the security mechanism. output_token_buffer Returns a token to pass to the context acceptor. STATUS CODES
The following status codes can be returned: The routine was completed successfully. The routine failed. See the minor_status parameter return value for more information. The supplied context handle did not refer to a valid context. AUTHOR
was developed by Sun Microsystems, Inc. SEE ALSO
gss_accept_sec_context(3), gss_init_sec_context(3), gss_process_context_token(3). The manpages for DCE-GSSAPI are included with the DCE-CoreTools product. To see those manpages add to gss_delete_sec_context(3)
All times are GMT -4. The time now is 04:07 PM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy