OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq Archives: Re: Altavista Free Internet Security

Re: Altavista Free Internet Security


Subject: Re: Altavista Free Internet Security
From: Bill (london222NETZERO.NET)
Date: Mon Jan 17 2000 - 16:28:19 CST


You can't run a trusted client on an untrusted machine.
A hostile user has complete access to the machine state, including
memory, stack, and register values. He/she can log all communication
between the client and the server and create a fake client that
duplicates the "authentification" procedure of the real client, but
without displaying ads.

It's a lost cause, but luckily for the people running the free
Internet access programs, most users won't do this.

__________________________________________
NetZero - Defenders of the Free World
Get your FREE Internet Access and Email at
http://www.netzero.net/download/index.html



This archive was generated by hypermail 2b27 : Tue Jan 18 2000 - 10:55:09 CST