Re: web info re: passport security problems?

From: S. Pidgorny [MVP] (slavickp@yahoo.com)
Date: 06/01/02


From: "S. Pidgorny [MVP]" <slavickp@yahoo.com>
Date: Sat, 1 Jun 2002 18:20:55 +1000


Robert,

Marc Slemko does great job finding vulnerabilities in systems that use
cookies. Microsoft responds adequately, by issuing patches to client
software and modifying server configuration to narrow down window of
opportunity for a cookie thief. I would actually recommend Microsoft's
security site, and also bugtraq mailing list and the rest of
securityfocus.com.

I believe that XML Web Services security, which allows to use PKI and
Kerberos Internet-wide, will once provide replacement for cookie-based
security.

--
Svyatoslav Pidgorny, MS MVP, MCSE
-= F1 is the key =-
"Robert Nagle" <idiotprogrammer@yahoo.com> wrote in message
news:fbef97c.0205312218.546e0a5c@posting.google.com...
> I just finished a fascinating article about the theoretically problems
> with the passport login system. http://avirubin.com/passport.html
>
> I also found the slemko article about a security hole
> http://alive.znep.com/~marcs/passport/
>
> Where is a good place to find the most current information about
> passport security problems/risks? is the official ms site a bad place
> for this information?
>
> Robert Nagle, Technical Writer Austin Texas
> http://www.imaginaryplanet.net/weblogs/asiafirst/


Relevant Pages

  • Re: Is Safe Mode is disabled?
    ... Please respond to newsgroup only. ... "Robert" wrote in message ... > of setting a password for the Administrator account. ... > All the XP security books I have seen discuss only the Pro edition. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Bass Burhglar Alarms
    ... Welcome back, Robert... ... And the bogus security codes on the BBA pages really ... > help with telephone sales. ... no more complaints get filed with the BBB!!! ...
    (alt.security.alarms)
  • Re: They can break ZoneAlarm easily !
    ... packet filter firewall or a port mapper or some other additional security. ... outlook express settings are restricted zone, ... Also, I'd try deleting your cookies, and then making sure in your internet ...
    (comp.security.firewalls)
  • Re: IE6 problems with verizon search
    ... Are you running WinXP SP2 or WinXP SP3? ... This step will help us clear cookies, restore the security level back ... Select the General tab, and in the Temporary Internet files window, click ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • [NEWS] Mozilla Cookie Stealing
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Cookies are often used to identify and authenticate users to a website. ... A bug in Mozilla allows an attacker to steal the user's cookies for any ... Mozilla has a bug that lets you bypass this protection and steal cookies ...
    (Securiteam)