<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Hacking without 0days: Drive-by Java</title>
	<atom:link href="http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Tue, 06 Jan 2009 10:28:59 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: goblert</title>
		<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/comment-page-1/#comment-122424</link>
		<dc:creator>goblert</dc:creator>
		<pubDate>Mon, 02 Jun 2008 20:02:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java#comment-122424</guid>
		<description>It is possible to make the applet download and run a executable. I have seen it with my own eyes. Its a very effective way to infect someone.</description>
		<content:encoded><![CDATA[<p>It is possible to make the applet download and run a executable. I have seen it with my own eyes. Its a very effective way to infect someone.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Drive-by Download: Where Network Security Meets WebAppSec &#124; Code in my Bug!!!</title>
		<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/comment-page-1/#comment-120118</link>
		<dc:creator>Drive-by Download: Where Network Security Meets WebAppSec &#124; Code in my Bug!!!</dc:creator>
		<pubDate>Sun, 27 Apr 2008 17:40:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java#comment-120118</guid>
		<description>[...] post was due since the Bank of India hack incident, and was fueled by PDP&#8217;s Drive-by Java post, which is a very simple, yet a well thought of extension (sort of) to the Drive-by Download attack. [...]</description>
		<content:encoded><![CDATA[<p>[...] post was due since the Bank of India hack incident, and was fueled by PDP&#8217;s Drive-by Java post, which is a very simple, yet a well thought of extension (sort of) to the Drive-by Download attack. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kbnet</title>
		<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/comment-page-1/#comment-101663</link>
		<dc:creator>kbnet</dc:creator>
		<pubDate>Sun, 20 Jan 2008 10:18:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java#comment-101663</guid>
		<description>Sorry, didn't post the URL:
http://www.aboulton.blogspot.com</description>
		<content:encoded><![CDATA[<p>Sorry, didn&#8217;t post the URL:<br />
<a href="http://www.aboulton.blogspot.com" rel="nofollow">http://www.aboulton.blogspot.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kbnet</title>
		<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/comment-page-1/#comment-101636</link>
		<dc:creator>kbnet</dc:creator>
		<pubDate>Sun, 20 Jan 2008 08:28:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java#comment-101636</guid>
		<description>This guy has a very interesting blog, he has a video which shows an applet patching a binary. Very nice!</description>
		<content:encoded><![CDATA[<p>This guy has a very interesting blog, he has a video which shows an applet patching a binary. Very nice!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Drive-by Download: Where Network Security Meets WebAppSec &#171; Hey! There is Code in my BUG!</title>
		<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/comment-page-1/#comment-64176</link>
		<dc:creator>Drive-by Download: Where Network Security Meets WebAppSec &#171; Hey! There is Code in my BUG!</dc:creator>
		<pubDate>Fri, 02 Nov 2007 13:17:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java#comment-64176</guid>
		<description>[...] on November 2nd, 2007  This post was due since the Bank of India hack incident, and was fueled by PDP&#8217;s Drive-by Java post, which is a very simple, yet a well thought of extension (sort of) to the Drive-by Download attack. [...]</description>
		<content:encoded><![CDATA[<p>[...] on November 2nd, 2007  This post was due since the Bank of India hack incident, and was fueled by PDP&#8217;s Drive-by Java post, which is a very simple, yet a well thought of extension (sort of) to the Drive-by Download attack. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mogano</title>
		<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/comment-page-1/#comment-63305</link>
		<dc:creator>mogano</dc:creator>
		<pubDate>Tue, 30 Oct 2007 22:24:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java#comment-63305</guid>
		<description>I've already done s.th. but not on Applets.
Therefore I asked because I don't think that they has increased the level of system rights.

Does someone know that writing (binary) files in (signed )Applets work???</description>
		<content:encoded><![CDATA[<p>I&#8217;ve already done s.th. but not on Applets.<br />
Therefore I asked because I don&#8217;t think that they has increased the level of system rights.</p>
<p>Does someone know that writing (binary) files in (signed )Applets work???</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/comment-page-1/#comment-63254</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Tue, 30 Oct 2007 19:49:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java#comment-63254</guid>
		<description>diesl0w, indeed!

mogano, DA BOMB? should we watch out for it?</description>
		<content:encoded><![CDATA[<p>diesl0w, indeed!</p>
<p>mogano, DA BOMB? should we watch out for it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mogano</title>
		<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/comment-page-1/#comment-63248</link>
		<dc:creator>mogano</dc:creator>
		<pubDate>Tue, 30 Oct 2007 19:38:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java#comment-63248</guid>
		<description>we call it:  DA BOMB! ;)</description>
		<content:encoded><![CDATA[<p>we call it:  DA BOMB! ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: diesl0w</title>
		<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/comment-page-1/#comment-63239</link>
		<dc:creator>diesl0w</dc:creator>
		<pubDate>Tue, 30 Oct 2007 18:33:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java#comment-63239</guid>
		<description>
Sounds like someones trying to compile a download/execute payload :)
</description>
		<content:encoded><![CDATA[<p>Sounds like someones trying to compile a download/execute payload :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sid</title>
		<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/comment-page-1/#comment-63224</link>
		<dc:creator>sid</dc:creator>
		<pubDate>Tue, 30 Oct 2007 17:38:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java#comment-63224</guid>
		<description>Some of us at Indiana University tried out this type of re-signing and modifying applets in a realistic scenario last year... you're right, it works very well.  People don't care about whether or not they should trust an executable; if they expect it, they will click yes no matter what.

Check out our results:
http://www.indiana.edu/~phishing/verybigad/</description>
		<content:encoded><![CDATA[<p>Some of us at Indiana University tried out this type of re-signing and modifying applets in a realistic scenario last year&#8230; you&#8217;re right, it works very well.  People don&#8217;t care about whether or not they should trust an executable; if they expect it, they will click yes no matter what.</p>
<p>Check out our results:<br />
<a href="http://www.indiana.edu/~phishing/verybigad/" rel="nofollow">http://www.indiana.edu/~phishing/verybigad/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/comment-page-1/#comment-63217</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Tue, 30 Oct 2007 16:54:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java#comment-63217</guid>
		<description>:) what are u building man?</description>
		<content:encoded><![CDATA[<p>:) what are u building man?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mogano</title>
		<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/comment-page-1/#comment-63208</link>
		<dc:creator>mogano</dc:creator>
		<pubDate>Tue, 30 Oct 2007 16:22:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java#comment-63208</guid>
		<description>Still only one question from me:

How do I download a File using a signed applet?


greetz,
mogano</description>
		<content:encoded><![CDATA[<p>Still only one question from me:</p>
<p>How do I download a File using a signed applet?</p>
<p>greetz,<br />
mogano</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jayjwa</title>
		<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/comment-page-1/#comment-63177</link>
		<dc:creator>jayjwa</dc:creator>
		<pubDate>Tue, 30 Oct 2007 14:07:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java#comment-63177</guid>
		<description>Works for Linux too, as long as the app. exists (ln -s xcalc calc for this example). It does put up a warning box and ask for confirmation that is obvious enough for me, but I can see how some people would click away without checking. Oddly, Firefox (2.0.0.7) also pops up an authenticaion box (bug?).</description>
		<content:encoded><![CDATA[<p>Works for Linux too, as long as the app. exists (ln -s xcalc calc for this example). It does put up a warning box and ask for confirmation that is obvious enough for me, but I can see how some people would click away without checking. Oddly, Firefox (2.0.0.7) also pops up an authenticaion box (bug?).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mogano</title>
		<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/comment-page-1/#comment-63176</link>
		<dc:creator>mogano</dc:creator>
		<pubDate>Tue, 30 Oct 2007 14:02:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java#comment-63176</guid>
		<description>how do I download a file for example??</description>
		<content:encoded><![CDATA[<p>how do I download a file for example??</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LiquidBrain</title>
		<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/comment-page-1/#comment-63166</link>
		<dc:creator>LiquidBrain</dc:creator>
		<pubDate>Tue, 30 Oct 2007 13:37:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java#comment-63166</guid>
		<description>Actually you can execute any command on system... start service, download file... you can do anything...</description>
		<content:encoded><![CDATA[<p>Actually you can execute any command on system&#8230; start service, download file&#8230; you can do anything&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mogano</title>
		<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/comment-page-1/#comment-63157</link>
		<dc:creator>mogano</dc:creator>
		<pubDate>Tue, 30 Oct 2007 12:54:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java#comment-63157</guid>
		<description>what can I do with signed Applets??

Also stuff like execute arbitary code (from outside)?
(if so, how?)</description>
		<content:encoded><![CDATA[<p>what can I do with signed Applets??</p>
<p>Also stuff like execute arbitary code (from outside)?<br />
(if so, how?)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/comment-page-1/#comment-63131</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Tue, 30 Oct 2007 11:23:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java#comment-63131</guid>
		<description>mogano, I am not sure what u are trying to say!</description>
		<content:encoded><![CDATA[<p>mogano, I am not sure what u are trying to say!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mogano</title>
		<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/comment-page-1/#comment-63113</link>
		<dc:creator>mogano</dc:creator>
		<pubDate>Tue, 30 Oct 2007 09:42:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java#comment-63113</guid>
		<description>Don't know that you get an attack working. How for example you can get some binary stuff (shellcode) running?? Thats only a exec command! Other things are not possible like write binfile or ???</description>
		<content:encoded><![CDATA[<p>Don&#8217;t know that you get an attack working. How for example you can get some binary stuff (shellcode) running?? Thats only a exec command! Other things are not possible like write binfile or ???</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Technocrat</title>
		<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/comment-page-1/#comment-62977</link>
		<dc:creator>Technocrat</dc:creator>
		<pubDate>Tue, 30 Oct 2007 02:46:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java#comment-62977</guid>
		<description>Good stuff pdp. 

The weakest link in security is the human element. Clearly things could be changed to better protect non-informed users from themselves...but in the end, the only solution is education.

By bringing issues like this into the light, you are helping educate people....nice work.</description>
		<content:encoded><![CDATA[<p>Good stuff pdp. </p>
<p>The weakest link in security is the human element. Clearly things could be changed to better protect non-informed users from themselves&#8230;but in the end, the only solution is education.</p>
<p>By bringing issues like this into the light, you are helping educate people&#8230;.nice work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java/comment-page-1/#comment-62855</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Mon, 29 Oct 2007 19:49:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hacking-without-0days-drive-by-java#comment-62855</guid>
		<description>Richard Moore, it is different when it comes to ActiveX controllers.

rezn, absolutely!

G-Brain, point taken! :)</description>
		<content:encoded><![CDATA[<p>Richard Moore, it is different when it comes to ActiveX controllers.</p>
<p>rezn, absolutely!</p>
<p>G-Brain, point taken! :)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
