FireGPG Passphrase And Cleartext Vulnerability

2008-10-20 Thread Mike Benham
Vulnerability Affecting FireGPG Passphrase and Cleartext Recovery 10/20/2008 Abstract FireGPG is a Firefox extension that provides a front-end to GPG, allowing webmail users to conveniently exchange GPG messages from Firefox

Outlook S/MIME Vulnerability

2002-09-02 Thread Mike Benham
=== Outlook S/MIME Vulnerability 09/02/02 Mike Benham <[EMAIL PROTECTED]> http://www.thoughtcrime.org === Abstract Outlook's S/MIME implem

IE SSL Exploit

2002-08-12 Thread Mike Benham
This is a follow-up to my previous advisory: http://online.securityfocus.com/archive/1/286290/2002-07-31/2002-08-06/0 Thanks to everyone who helped verify the vulnerability. I've written a small tool (sslsniff) that demonstrates the severity of this vulnerability in a real-world setting. It pe

Re: IE SSL Vulnerability

2002-08-09 Thread Mike Benham
On Wed, 7 Aug 2002, Alex Loots wrote: > Hi Mike, > I visited your demo at https://www.thoughtcrime.org. It appears that Thawte is > the TTP instead of Verisign. Does this make any difference for example the > certificate extensions? First of all, https://www.thoughtcrime.org is NOT the demo site