Re: [Full-disclosure] Overtaking Google Desktop

2007-02-22 Thread Yair Amit
In November of 2005, Matan Gillon discovered a vulnerability in Internet Explorer in the way it handled the CSS import directive (http://www.hacker.co.il/security/ie/css_import.html). He proved the danger of the IE vulnerability by attacking Google Desktop. This proof of concept proved a powerfu

Re: [Full-disclosure] Overtaking Google Desktop

2007-02-22 Thread Steve Ragan
Ragan Cc: 'Steven Scheffler'; 'pdp (architect)'; 'Yair Amit'; full-disclosure@lists.grok.org.uk Subject: Re: [Full-disclosure] Overtaking Google Desktop On Thu, 22 Feb 2007, Steve Ragan wrote: > Yea he uses it later in the video, you see him pull it up in the > a

Re: [Full-disclosure] Overtaking Google Desktop

2007-02-21 Thread Michal Zalewski
On Thu, 22 Feb 2007, Steve Ragan wrote: > Yea he uses it later in the video, you see him pull it up in the attack, and > read it. One would assume it is fake. [lights dim, sinister accords play] ...OR IS IT? /mz ___ Full-Disclosure - We believe in

Re: [Full-disclosure] Overtaking Google Desktop

2007-02-21 Thread Steve Ragan
); Yair Amit Cc: full-disclosure@lists.grok.org.uk Subject: Re: [Full-disclosure] Overtaking Google Desktop Hey, there is a passwords.txt showing on the 3rd slide :) intentional? ;) -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of pdp (architect) Sent: Wednesday

Re: [Full-disclosure] Overtaking Google Desktop

2007-02-21 Thread Steven Scheffler
-disclosure] Overtaking Google Desktop This is quite interesting although it is a concept that has been developed on sla.ckers.org some time ago. I love the presentation... brilliant. On 2/21/07, Yair Amit <[EMAIL PROTECTED]> wrote: > Hello, > > A new research from Watchfire has rev

Re: [Full-disclosure] Overtaking Google Desktop

2007-02-21 Thread pdp (architect)
This is quite interesting although it is a concept that has been developed on sla.ckers.org some time ago. I love the presentation... brilliant. On 2/21/07, Yair Amit <[EMAIL PROTECTED]> wrote: > Hello, > > A new research from Watchfire has revealed a serious vulnerability in > Google Desktop. > >

[Full-disclosure] Overtaking Google Desktop

2007-02-21 Thread Yair Amit
Hello, A new research from Watchfire has revealed a serious vulnerability in Google Desktop. The attack, which is fully presented in a new Watchfire research paper released today (available at http://www.watchfire.com/resources/Overtaking-Google-Desktop.pdf), can allow a malicious individual to a