![]() ![]() |
Oct 19 2006, 11:08 AM
Post
#16
|
|
![]() Group: Members Posts: 10,620 Joined: 23-February 06 From: Houston, TX Member No.: 48 |
I see what the guy is saying, but that's not how most websites work. Sure, I go to www.bankofamerica.com, but once I log in I end up at like https://servername123.bankofamerica.com/bin...f9a0j3409f/blah. Now unless there's a way to get the address bar for another open window, this exploit wont really ever get any information I care about. It would work for less secure sites like facebook, but it's not like people keep their bank account info on there. You could also bypass this by telling IE to run windows in a separate process (which is good anyhow bc it isolates each browsing session).
|
|
|
|
Oct 21 2006, 02:28 AM
Post
#17
|
|
![]() Retired Funk-bringer Group: Moderators Posts: 2,656 Joined: 22-February 06 From: Dallas Member No.: 14 |
It would work for less secure sites like facebook, but it's not like people keep their bank account info on there. You could also bypass this by telling IE to run windows in a separate process (which is good anyhow bc it isolates each browsing session). You'd be surprised at the information people keep on their facebook. Besides, all you need is their facebook email and password, and at least half the time that gives you access to whatever else. I speak from experience here. People get bank shit emailed to them all the time, then say they use the same password there, etc etc, identity theft ahoy. Sounds like a leap, but considering i've had the resources (and accounts) to do it, with nothing but my conscience keeping me back (i still nosed around though, I got into her photobucket O:P), i assure you, it's extremely feasable. -------------------- WAIT. I'm not finished.
|
|
|
|
Oct 21 2006, 12:18 PM
Post
#18
|
|
![]() Group: Members Posts: 10,620 Joined: 23-February 06 From: Houston, TX Member No.: 48 |
but you couldn't extract a password using this technique.
|
|
|
|
Oct 22 2006, 12:15 AM
Post
#19
|
|
![]() Retired Funk-bringer Group: Moderators Posts: 2,656 Joined: 22-February 06 From: Dallas Member No.: 14 |
have to admit, i didn't fully read it.
still, the idea of a new browser is to plug security holes. -------------------- WAIT. I'm not finished.
|
|
|
|
Oct 22 2006, 11:00 AM
Post
#20
|
|
![]() Group: Members Posts: 10,620 Joined: 23-February 06 From: Houston, TX Member No.: 48 |
yeah, here's a quick summary of how it works:
1. you navigate to malicious site 2. malicious web site attempts to open a web page using simple javascript (all programmatically, it's basically getting the stream of html, the user wouldn't see this) 3. if you happened to be currently logged into a website, they can open and see the same site, provided they guess correctly what site to try. so, for this thing to work, you have to be at a common website and logged in (say www.facebook.com), and then browse to the malicious site. then, the malicious site would have to have www.facebook.com in its list of sites to check. the malicious site could then "open" www.facebook.com in the context of your browser, which in this case would show them your facebook "home" page. now since facebook doesn't have ID's in the links to edit your profile (ie the link is something like this http://ttu.facebook.com/editprofile.php), they could potentially get whatever info you have in there, and possibly change it. the impracticality here is that any site with useful information (like banks) are not going to save your password, and even if they did, they take you to some URL with a long ass ID attached. so once I log into bankofamerica.com, i really end up at bankofamerca.com/blah/blah/asdf?23ti2otj2o3ijt2093tj2039jt023jt, which the malicious site would have no way to guess or get to. even if for some crazy reason they could guess that long url, bank sites (at least mine) don't ever list full account numbers or pins/passwords. so in a best case scenario they could see my balance. also the malicious site would have to have an extremely large number of websites to check for it to even have a chance of finding one it could use. it would also have to "navigate" to all of these sites, which would at the very least bog the user's connection. so yeah i agree this is pretty shitty that it can happen and think it should be fixed, but i'm not all that worried about it stealing important information. |
|
|
|
Oct 22 2006, 11:52 AM
Post
#21
|
|
![]() From Atlantis to Interzone Group: Global Moderators Posts: 2,512 Joined: 23-February 06 From: Somewhere in space and time Member No.: 65 |
yeah, here's a quick summary of how it works: 1. you navigate to malicious site 2. malicious web site attempts to open a web page using simple javascript (all programmatically, it's basically getting the stream of html, the user wouldn't see this) 3. if you happened to be currently logged into a website, they can open and see the same site, provided they guess correctly what site to try. so, for this thing to work, you have to be at a common website and logged in (say www.facebook.com), and then browse to the malicious site. then, the malicious site would have to have www.facebook.com in its list of sites to check. the malicious site could then "open" www.facebook.com in the context of your browser, which in this case would show them your facebook "home" page. now since facebook doesn't have ID's in the links to edit your profile (ie the link is something like this http://ttu.facebook.com/editprofile.php), they could potentially get whatever info you have in there, and possibly change it. the impracticality here is that any site with useful information (like banks) are not going to save your password, and even if they did, they take you to some URL with a long ass ID attached. so once I log into bankofamerica.com, i really end up at bankofamerca.com/blah/blah/asdf?23ti2otj2o3ijt2093tj2039jt023jt, which the malicious site would have no way to guess or get to. even if for some crazy reason they could guess that long url, bank sites (at least mine) don't ever list full account numbers or pins/passwords. so in a best case scenario they could see my balance. also the malicious site would have to have an extremely large number of websites to check for it to even have a chance of finding one it could use. it would also have to "navigate" to all of these sites, which would at the very least bog the user's connection. so yeah i agree this is pretty shitty that it can happen and think it should be fixed, but i'm not all that worried about it stealing important information. Your bank have bill pay? That's another way that they can get to your money. Also, at least at Wells Fargo, they can get at your account number if they look on your statement online. It's there a lot of times, it's just a bit harder to find. -------------------- Holy shit, pebkac, you're awesome! "Be who you are and say what you feel, because those who mind don't matter and those who matter don't mind." - Theodor Seuss Geisel (AKA Dr. Seuss) "An idea that is not dangerous is unworthy of being called an idea at all." - Oscar Wilde |
|
|
|
Oct 22 2006, 10:35 PM
Post
#22
|
|
![]() Group: Members Posts: 10,620 Joined: 23-February 06 From: Houston, TX Member No.: 48 |
Your bank have bill pay? That's another way that they can get to your money. Also, at least at Wells Fargo, they can get at your account number if they look on your statement online. It's there a lot of times, it's just a bit harder to find. well not using this method. although i don't use wells fargo, i'm going to guess they at least have the same system of, browse to www.wellsfargo.com, log in, now you're redirected to blah1.wellsfargo.com/asdf/blah/bs.blah?jf03jf0293jf09j32flsioj923ur902u3r09. in these cases this particular technique of hacking would be useless. but yeah man that is pretty unsecure if your full bank account number is displayed on the screen when you're logged in. bank of america will just show the last few digits of each account. |
|
|
|
Oct 26 2006, 09:32 AM
Post
#23
|
|
![]() From Atlantis to Interzone Group: Global Moderators Posts: 2,512 Joined: 23-February 06 From: Somewhere in space and time Member No.: 65 |
Does anyone know of any place where you can get new themes for IE 7? The default is ugly as hell.
-------------------- Holy shit, pebkac, you're awesome! "Be who you are and say what you feel, because those who mind don't matter and those who matter don't mind." - Theodor Seuss Geisel (AKA Dr. Seuss) "An idea that is not dangerous is unworthy of being called an idea at all." - Oscar Wilde |
|
|
|
Oct 26 2006, 09:51 AM
Post
#24
|
|
![]() Group: Members Posts: 10,620 Joined: 23-February 06 From: Houston, TX Member No.: 48 |
yeah it was pretty much designed for vista so it does look kinda weird without the aero interface
|
|
|
|
Oct 26 2006, 10:02 AM
Post
#25
|
|
![]() Group: Admin Posts: 3,403 Joined: 23-February 06 From: PDX/TXL Member No.: 35 |
yeah it was pretty much designed for vista so it does look kinda weird without the aero interface I thought IE7+ was specifically for Vista with IE7(-) being for everything else?? -------------------- "There is a level of cowardice lower than that of the conformist: that of the fashionable non-conformist." |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 21st August 2026 - 03:46 PM |