Firefox Observation Plugin Attack

看板Bugtraq作者時間16年前 (2010/01/29 02:32), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
Hi, What is the level of trust we have to give into valuable firefox plugins? (potentially without checking the provided signatures or hashes, if available). Altering the plugin functionality into an observation plugin is just an easy task and I strongly recommend to work with empty firefox profiles.=20 "./firefox -P --no-remote" Watch the movie on Hacking-Lab to understand the firefox observation hack.=20 http://www.hacking-lab.com/download/ =09 Regards Ivan Buetler Compass Security, Switzerland www.csnc.ch --- SWISS CYBER STORM III - WARGAMES - CTF - May 2011 ---
文章代碼(AID): #1BOTWbIX (Bugtraq)