https MITM attack via user page


 
Thread Tools Search this Thread
Special Forums Cybersecurity https MITM attack via user page
# 8  
Old 05-29-2011
StrongVPN decided to delete the log mentioned above for security reasons. However attached is I hope a version that is sufficiently anonymised.

In a nutshell, StrongVPN is a cert. based VPN rather than password/key, and so while they have numbers of servers, you have to download a new cert. when changing. Each time I changed server openvpn failed to connect twice before making the connection (with the same errors) openvpn though connecting first time thereafter. I experienced the mouse cursor jumping from the password text input box to the clear text login name box and of its own accord shortly after this, which I take as a MITM attack of some sort (same one website, repeated - namely delicious login).

Last edited by GSO; 05-29-2011 at 10:41 AM..
# 9  
Old 06-04-2011
I'm taking the opportunity to make a quick test post (experimenting with browsers - I am always without fail hacked on this page!) while bringing this log up to date. I've taken the problem over to a thread on the Fedora SELInux forum which can be found here:

mouse pointer stuck in browser sandbox window

I also moved from SL6 over to Fedora 15 to try a current browser version out (SL6 is still using FF 3.X releases). The same bugs result though.

In a nutshell, with an install that should not have (at least in theory) been breached by an attacker gaining direct access to the keyboard, hackers can still hack the browser (running in a SELInux sandbox) -- but they don't seem to be able to hack the webpages so the encrypted VPN connection seems to be holding out - it is hacks like locking the mouse in the sandbox window, and crashing flash, that are getting through (I am fairly well sure at this stage that these are hacks).

Last edited by GSO; 06-19-2011 at 09:31 AM..
# 10  
Old 06-19-2011
For anyone interested I have continued this over on MozillaZine Firefox bugs forum:

VPN encryption not broken, but FF hacked? • mozillaZine Forums
Login or Register to Ask a Question

Previous Thread | Next Thread

5 More Discussions You Might Find Interesting

1. Solaris

Need suggestion:- Failed HTTPS transfer to https://supportfiles.sun.com/curl

Hi Guys, I have recently started reciving below Error message Failed HTTPS transfer to https://supportfiles.sun.com/curl whenever I run /usr/local/bin/sudo /opt/SUNWexplo/bin/explorer -P -q -v from all Servers. Looks like the SSL certificate as Expired. Whenever I type... (4 Replies)
Discussion started by: manalisharmabe
4 Replies

2. UNIX for Dummies Questions & Answers

How to switch the user before executing a shell script from web page??

hi, i want to execute a shell script as a different user. the flow is like this. there is a html web page from which i have to call a shell script. web server is apache. to call the shell script from html page, a perl script is required. so the html page calls the perl script and the perl... (2 Replies)
Discussion started by: Little
2 Replies

3. Shell Programming and Scripting

help pulling ${VARS} out of a web page user curl

Here is the code I have so far #!/bin/bash INFOF="/tmp/mac.info" curl --silent http://www.everymac.com/systems/apple/macbook_pro/specs/macbook-pro-core-2-duo-2.8-aluminum-17-mid-2009-unibody-specs.html "$INFOF" I want help putting these specs into a vars Standard Ram: value into $VAR1... (1 Reply)
Discussion started by: briandanielz
1 Replies

4. What is on Your Mind?

Fedora Man Pages Reported Attack Page?

Is firefox complaining to anyone else that this is a Reported Attack Page!? I have used this site a million times and now it feels like complaining. Fedora Manpages: Home (5 Replies)
Discussion started by: cokedude
5 Replies

5. Web Development

HTTPS-Home Page issue.

Hi Folks, This might be a very question,but i have not been able to find the solution. While accessing http://16.138.32.128/ in my LAN, i am able to read the index.html placed in DocumentRoot(/var/www/html). However if i tab in https://xx.xx.xx.xx/ ,i am only able to access the default... (0 Replies)
Discussion started by: Hari_Ganesh
0 Replies
Login or Register to Ask a Question