Forum     

Go Back   Digit Technology Discussion Forum > News > Random News
Register FAQ Calendar Mark Forums Read

Random News Non-technology news that you feel members should know about. NOTE: Sources to be mentioned at the beginning of each post.


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 18-05-2007, 06:27 AM   #1 (permalink)
In The Zone
 
morpheusv6's Avatar
 
Join Date: Dec 2006
Location: Bangalore
Posts: 216
Unhappy Do you know what’s leaking out of your browser?


Just saw this on zdnet.com. Great article, scary though.

Information seeping out of your Web browser could provide a gold mine for hackers doing reconnaissance for targeted attacks.
At the ToorCon Seattle (beta) conference, Web application security specialist Robert Hansen (RSnake) demoed Mr-T (Master Recon-Tool), a new utility that combines information disclosure flaws in Internet Explorer and Firefox to collect information on a target's computer system.
For a basic idea of the kinds of information your browser is willingly coughing up, click on this link and you'll see a snapshot of your machine, including the browser version, the add-ons installed and enabled, your ISP hostname, a list of previously visited Web sites and, in some instances, your Gmail address.
RSnake explains:
Mr. T combines all that into one place so that you can gather a great deal of client based info through a single XSS hole. Then by taking the DOM and dumping it into a form that you submit to a logging server, you can know pretty much everything you want to know about breaking into the machine in question.

Basically, a hacker can lure a specific target to a Web site and collect enough information to prepare an attack. This becomes even more scary when you take into account that even before you visit a Web site, your computer is already broadcasting all kinds of data that can be used to prepare a solid profile of a target.
Earlier this year at Black Hat DC, Errata Security's Robert Graham released Ferret, a souped-up sniffer that gathers all the benign data that seeps out when you turn on your computer. For example, even before your machine fully boots up, it is already broadcasting the list of Wi-Fi access-points you've got cached on your computer, the previous IP address you used (requested by DHCP), your NetBIOS name, your login ID, and a list of servers (via NetBIOS request) you want connections to.
Combine the data from Ferret with a reconnaissance tool like Mr-T and you can get a basic idea of the data your machine is broadcasting to the world.
Another tool I saw recently that fits into this data profiling realm is Evolution, a data correlation/search utility written by South African hacker Roelof Temmingh. Evolution, which is currently in beta, provides an interface to connect publicly available data.
The idea behind Evolution fits into the Mr-T/Ferret concept because you can basically type in a person's name into the search interface and see how that name connects to domain names, IP addresses, telephone numbers and other things of interest to an attacker.
When I chatted with Temmingh at CanSecWest earlier this year, he was positioning Evolution as a forensics tool for law enforcement and other investigators but, anyone with access to a database of valuable information (think about Ferret's output) can build out a fairly solid profile of a target.
Once you know what's running on your target's machine, the types of sites he visits, the company he keeps (say, MySpace or LinkedIn connections), you can easily prepare an attack.
What's even more scary is there's very little you can do about it.




source: http://blogs.zdnet.com/security/?p=197&tag=nl.e622
__________________
Deven
morpheusv6 is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 18-05-2007, 12:53 PM   #2 (permalink)
ax3
Cool as a CUCUMBAR ! ! !
 
ax3's Avatar
 
Join Date: Dec 2003
Posts: 5,052
Default Re: Do you know what’s leaking out of your browser?

DAMN scary man ...............


"SO V R HUNTED BY ANY smart HUNTER " ..................
ax3 is offline  
Old 18-05-2007, 01:38 PM   #3 (permalink)
Alpha Geek
 
eagle_y2j's Avatar
 
Join Date: Nov 2004
Location: Himalayas
Posts: 719
Default Re: Do you know what’s leaking out of your browser?

Code:
Master Reconnaissance Tool
Environmental variables:

    HTTP_ACCEPT = */*
    HTTP_ACCEPT_CHARSET = ISO-8859-1,utf-8;q=0.7,*;q=0.7
    HTTP_ACCEPT_ENCODING = gzip,deflate
    HTTP_ACCEPT_LANGUAGE = en-us,en;q=0.5
    HTTP_CONNECTION = keep-alive
    HTTP_KEEP_ALIVE = 300
    HTTP_USER_AGENT = Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.3) Gecko/20061201 Firefox/2.0.0.3 (Ubuntu-feisty)
    REMOTE_ADDR = 59.94.141.**
    REMOTE_PORT = 50305
    REQUEST_METHOD = GET
    SERVER_PROTOCOL = HTTP/1.1

Derived Information:

    It appears you are not using Tor

Browser detection:

    IE7.0 not detected
    JavaScript Version: 1.7
    Browser type: Netscape
    User Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.3) Gecko/20061201 Firefox/2.0.0.3 (Ubuntu-feisty)
    User Language: en-US
    Cookies Enabled: true
    Application Version: 5.0 (X11; en-US)
    Platform: Linux i686
    Application Code Name: Mozilla
    OS CPU: Linux i686
    On line: true
    Product: Gecko
    Product Sub: 20061201
    Application Code Name: Mozilla
    Java Enabled: true
    Your Intranet IP:
    Document referrer: http%3A//www.thinkdigit.com/forum/showthread.php%3Fp%3D501889

Browser Plugins (5):

    * Plugin name: Totem Web Browser Plugin 2.18.1
          o Filename: libtotem-basic-plugin.so
          o Description: The Totem 2.18.1 plugin handles video and audio streams.
          o Mime info: application/ogg Ogg multimedia ogg enabled
          o Mime info: video/mpeg MPEG video mpg, mpeg, mpe enabled
          o Mime info: audio/wav WAV audio wav enabled
          o Mime info: audio/mpeg MP3 audio mp3 enabled 
    * Plugin name: Windows Media Player Plug-in 10 (compatible; Totem)
          o Filename: libtotem-gmp-plugin.so
          o Description: The Totem 2.18.1 plugin handles video and audio streams.
          o Mime info: application/x-mplayer2 AVI video avi, wma, wmv enabled
          o Mime info: video/x-ms-asf-plugin ASF video asf, wmv enabled
          o Mime info: video/x-msvideo AVI video asf, wmv enabled
          o Mime info: video/x-ms-asf ASF video asf enabled
          o Mime info: video/x-ms-wmv WMV video wmv enabled
          o Mime info: video/x-wmv WMV video wmv enabled
          o Mime info: video/x-ms-wvx Playlist wmv enabled
          o Mime info: video/x-ms-wm ASF video wmv enabled 
    * Plugin name: DivX® Web Player
          o Filename: libtotem-mully-plugin.so
          o Description: The Totem 2.18.1 plugin handles video and audio streams.
          o Mime info: video/divx AVI video divx enabled 
    * Plugin name: QuickTime Plug-in 7.1.3
          o Filename: libtotem-narrowspace-plugin.so
          o Description: The Totem 2.18.1 plugin handles video and audio streams.
          o Mime info: video/quicktime QT video mov enabled
          o Mime info: video/mp4 MPEG-4 video mp4 enabled
          o Mime info: image/x-macpaint MacPaint Bitmap image pntg enabled
          o Mime info: image/x-quicktime Macintosh Quickdraw/PICT drawing pict, pict1, pict2 enabled 
    * Plugin name: Shockwave Flash
          o Filename: libflashplayer.so
          o Description: Shockwave Flash 9.0 r31
          o Mime info: application/x-shockwave-flash Shockwave Flash swf enabled
          o Mime info: application/futuresplash FutureSplash Player spl enabled 


Firefox plugin detection:


JavaScript variables:

    Window width = 1024
    Window height = 573
    Available Screen Height = 719
    Available Screen Width = 1024
    Color Depth = 16
    Pixel Depth = 16

Some sites you have visited:

    * http://mail.google.com/
    * http://mail.yahoo.com/
    * http://www.blogger.com/
    * http://www.yahoo.com/

Local host (Note: if Localrodeo is installed this may not work):
this is normal detection report for server we connect ?isn't it
__________________
Registered LINUX USER #438929
eagle_y2j is offline  
Old 18-05-2007, 02:14 PM   #4 (permalink)
C# Be Sharp !
 
Zeeshan Quireshi's Avatar
 
Join Date: Jun 2006
Location: Toronto
Posts: 1,805
Default Re: Do you know what’s leaking out of your browser?

Quote:
Originally Posted by ax3
DAMN scary man ...............


"SO V R HUNTED BY ANY smart HUNTER " ..................
this is the normal stuff sent by the HTTP protocol , nothin to be scared bout .

coz if u see all da headers send by your browser in a normal browsing session , it will boggle you
__________________
There are 10 types of people in the world: those who understand binary and those who do not.
Zeeshan Quireshi is offline  
Old 18-05-2007, 02:19 PM   #5 (permalink)
String Phreak
 
mediator's Avatar
 
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,457
Default Re: Do you know what’s leaking out of your browser?

Turn off "Javascript" and then try!
__________________
Bad Bad server.....No candy for u!
mediator is offline  
Old 18-05-2007, 02:40 PM   #6 (permalink)
The Devil
 
blackpearl's Avatar
 
Join Date: Feb 2006
Location: 0x02AE88C6FF
Posts: 983
Default Re: Do you know what’s leaking out of your browser?

^^ LOL!! so it depend on javascript!! Pretty lame.
blackpearl is offline  
Old 18-05-2007, 02:44 PM   #7 (permalink)
String Phreak
 
mediator's Avatar
 
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,457
Default Re: Do you know what’s leaking out of your browser?

It seems pretty obvious and simple to me. Its a hacker's site and some lamer guy just wanna show his noobie skills!
__________________
Bad Bad server.....No candy for u!
mediator is offline  
Old 18-05-2007, 08:05 PM   #8 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default Re: Do you know what’s leaking out of your browser?

i get a blank page !?
with error acess denied to code
(vista ulti/maxthon on ie7/kis)
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 18-05-2007, 08:09 PM   #9 (permalink)
The Devil
 
blackpearl's Avatar
 
Join Date: Feb 2006
Location: 0x02AE88C6FF
Posts: 983
Default Re: Do you know what’s leaking out of your browser?

^^ Thats good to know. So ie7 on Vista seems good.
blackpearl is offline  
Old 18-05-2007, 08:37 PM   #10 (permalink)
left this forum longback
 
praka123's Avatar
 
Join Date: Sep 2005
Location: -
Posts: 7,536
Default Re: Do you know what’s leaking out of your browser?

^^ ofcourse without java enabled?
__________________
left this forum long back.Admin Can Delete this Account and posts Permanantly.Thank You
Get GNU/Linux - http://getgnulinux.org
praka123 is offline  
Old 18-05-2007, 09:14 PM   #11 (permalink)
The pWnster
 
Vyasram's Avatar
 
Join Date: Oct 2004
Location: Karaikudi,TN
Posts: 841
Default Re: Do you know what’s leaking out of your browser?

how's this



detecting such things is nothing
__________________
Sigs suck
Vyasram is offline  
Old 18-05-2007, 10:03 PM   #12 (permalink)
Alpha Geek
 
eagle_y2j's Avatar
 
Join Date: Nov 2004
Location: Himalayas
Posts: 719
Default Re: Do you know what’s leaking out of your browser?

but wat bout email address ?
__________________
Registered LINUX USER #438929
eagle_y2j is offline  
Old 18-05-2007, 10:44 PM   #13 (permalink)
HELP AND SUPPORT
 
rakeshishere's Avatar
 
Join Date: Jun 2006
Posts: 1,603
Default Re: Do you know what’s leaking out of your browser?

I Feel..if any1 is on internet..He is not Alone
There is No Full protection,Privacy and security present all the Time
rakeshishere is online now  
Old 25-05-2007, 08:22 PM   #14 (permalink)
King of my own Castle
 
freshseasons's Avatar
 
Join Date: May 2004
Location: Humor and wit.
Posts: 1,249
Default Re: Do you know what’s leaking out of your browser?

Quote:
Originally Posted by eagle_y2j
but wat bout email address ?
I cant see the email option anywhere when i click the link.I dont know how it detected your..!
What Os are you using ...and the java runtime is it 1.6.0 or later..?
__________________
Never take life seriously. Nobody gets out alive anyway.
freshseasons is offline  
Old 30-05-2007, 01:54 PM   #15 (permalink)
Alpha Geek
 
eagle_y2j's Avatar
 
Join Date: Nov 2004
Location: Himalayas
Posts: 719
Default Re: Do you know what’s leaking out of your browser?

Quote:
Originally Posted by freshseasons
I cant see the email option anywhere when i click the link.I dont know how it detected your..!
What Os are you using ...and the java runtime is it 1.6.0 or later..?
I m using Suse 10.2 with no JAVA ....but it didn't detected my address also I was concern with screenshot with mail address
__________________
Registered LINUX USER #438929
eagle_y2j is offline  
Old 17-07-2007, 12:47 AM   #16 (permalink)
"The Gentleman"
 
vish786's Avatar
 
Join Date: Sep 2006
Posts: 1,434
Post Re: Do you know what’s leaking out of your browser?

wow unbelievable. <shocks>
__________________
"The use of COBOL cripples the mind; its teaching should, therefore, be regarded as a criminal offense."
- Dijkstra
vish786 is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
I need a PDF Browser vickymustdie Software Q&A 1 19-04-2007 05:58 PM
Which Browser are you using? shashank_digitreader Technology News 9 26-10-2006 10:35 PM
which is the best browser right now vikramkh QnA (read only) 4 17-01-2006 02:06 PM
Best browser Varunnagwekar QnA (read only) 2 20-05-2005 04:17 PM
Best browser Varunnagwekar QnA (read only) 1 20-05-2005 01:14 PM

 
Latest Threads
- by Who
- by icebags
- by Krow
- by gohan89

Advertisement




All times are GMT +5.5. The time now is 06:56 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2