Re: [Full-disclosure] Overtaking Google Desktop

2007-02-22 Thread Steve Ragan
Ragan Cc: 'Steven Scheffler'; 'pdp (architect)'; 'Yair Amit'; full-disclosure@lists.grok.org.uk Subject: Re: [Full-disclosure] Overtaking Google Desktop On Thu, 22 Feb 2007, Steve Ragan wrote: Yea he uses it later in the video, you see him pull it up in the attack, and read it. One would assume

Re: [Full-disclosure] Overtaking Google Desktop

2007-02-22 Thread Yair Amit
In November of 2005, Matan Gillon discovered a vulnerability in Internet Explorer in the way it handled the CSS import directive (http://www.hacker.co.il/security/ie/css_import.html). He proved the danger of the IE vulnerability by attacking Google Desktop. This proof of concept proved a

[Full-disclosure] Overtaking Google Desktop

2007-02-21 Thread Yair Amit
Hello, A new research from Watchfire has revealed a serious vulnerability in Google Desktop. The attack, which is fully presented in a new Watchfire research paper released today (available at http://www.watchfire.com/resources/Overtaking-Google-Desktop.pdf), can allow a malicious individual to

Re: [Full-disclosure] Overtaking Google Desktop

2007-02-21 Thread Michal Zalewski
On Thu, 22 Feb 2007, Steve Ragan wrote: Yea he uses it later in the video, you see him pull it up in the attack, and read it. One would assume it is fake. [lights dim, sinister accords play] ...OR IS IT? /mz ___ Full-Disclosure - We believe in