And there's also Echo Mirage [http://www.bindshell.net/tools/echomirage], which 
can hook an executable that's using SSL connections, and dump the plaintext.

Basically, if they own the box, they can do whatever they want...  I don't 
think too many admins would do this though (unless you pissed them off).

-Dave


From: [email protected] 
[mailto:[email protected]] On Behalf Of Chris Merkel
Sent: Monday, December 14, 2009 4:52 PM
To: PaulDotCom Security Weekly Mailing List
Subject: Re: [Pauldotcom] Can a sys admin see a gmail account

If you're using a corporate asset, a sysadmin could install software to record 
all of your screen actions, keystrokes, copy everything off your HDD without 
you knowing, monitor all your network traffic, etc. Worrying about SSL in that 
context would be a bit silly.

My recommendation, if you're really concerned about it, would to bring your own 
netbook + EVDO card to work if you need any semblance of privacy.

- Chris
On Mon, Dec 14, 2009 at 2:30 PM, Shawn McGovern 
<[email protected]<mailto:[email protected]>> wrote:
Ok so my question was posted in a forum and someone gave me and answer but 
didnt explain it and then the forum post was when closed on me.  So I will ask 
here for clarity and try not to kill me for this, I am trying to learn.

So if someone uses a corporate network to check a Gmail (using SSL).  If they 
check to make sure that they have a secure connection -- once connected -- and 
then they check the certificate to see if the cert hierarchy has been tampered 
with.  Everything looks fine.  Are any admin or whomever able to see you 
emails?  Forget about software on the computer you are using, only through the 
network monitoring.

I was told in the forum that they could use a monitoring program like wireshark 
to view them.  In the wireshark forum I read that you would need the private 
key to decrypt the messages and in the forum they said that a sys admin can get 
the private key?  Is that information correct?  and if so how would they be 
able to get the private key?


Thanks in advance

_______________________________________________
Pauldotcom mailing list
[email protected]<mailto:[email protected]>
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com



--
- Chris Merkel
_______________________________________________
Pauldotcom mailing list
[email protected]
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com

Reply via email to