Re: [Full-Disclosure] http://www.chase.com/ vulnerability

From: Perry E. Metzger (perry_at_piermont.com)
Date: 05/28/04

  • Next message: Michael Tokarev: "[Full-Disclosure] Re: Linux Kernel sctp_setsockopt() Integer Overflow"
    To: <gauntlet@nym.hush.com>
    Date: Fri, 28 May 2004 15:30:17 -0400
    
    

    <gauntlet@nym.hush.com> writes:
    > Many financial institutions do the same thing.
    >
    > www.americanexpress.com:
    >
    > Security is important to everyone!
    >
    > Please be assured that, although the home page itself does not have an
    > "https" URL, the login component of this page is secure. When you enter your
    > User ID and password, your information is transmitted via a secure
    > environment,

    Except you have no way to know that without reading the html, since
    someone could have intercepted and altered the form. Given how many
    people can or will read the html, the assurances are completely false
    and essentially constitute a way of training their customers to have
    their accounts taken over in the future.

    -- 
    Perry E. Metzger		perry@piermont.com
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Michael Tokarev: "[Full-Disclosure] Re: Linux Kernel sctp_setsockopt() Integer Overflow"

    Relevant Pages

    • Re: Bank Exploit
      ... IMHO the only solution is to tell a security community such as a mailing list or SANS or whatever what the problem is a do it anonymously to avoid further troubles. ... As a matter of fact it is the financial institutions responsibility to care about there own security so either they have implemented something so that you could push the information to them either they don't for business/marketing purpose and they should retrieve the information from a public area. ... Subject: Bank Exploit ... such as - how did you discover the vulnerability in the first place. ...
      (Security-Basics)
    • RE: Protecting Web Files from Direct Access
      ... built-in security of a kind. ... Forms Authentication automatically redirects users who access pages on your ... I'm trying to figure out how to rewrite an HTML ... page so that it performs the function of the HTML whilst being an ASPX page. ...
      (microsoft.public.dotnet.security)
    • Re: [SLE] Proposal:TML. HTML without the H for markind up mail, etc.
      ... On Sunday 15 February 2004 01:52, Vince Littler wrote: ... >> It is not objectionable ONLY because of security issues, ... HTML is not a complete ... > plain ascii than ever you could with formatting. ...
      (SuSE)
    • Re: arrange form data in same order as on form
      ... > That conversion is done at a later stage, since HTML ... scripts exhibit very little security risk, ... another approach is to disallow just enough data characters ... effective planning and even smaller with very good planning. ...
      (comp.lang.perl.misc)
    • Re: Security says javascript mouseovers are Dangerous ????
      ... > I had a similar situtation with local HTML files used as custom start ... >security feature: ... >> dangerous activeX blah blah blah, so I have to 'allow' my own page to load ... >> There is *no* activeX or flash on this page. ...
      (microsoft.public.windowsxp.general)