One more reason to use NoScript - it would have made the CSRF significantly harder to pull off. And a reason to use an OS with a proper package manager, of course ;)
" />
Is the corresponding 1-click that works on noscript.41–50 of 96 posts
One more reason to use NoScript - it would have made the CSRF significantly harder to pull off. And a reason to use an OS with a proper package manager, of course ;)
" />
Is the corresponding 1-click that works on noscript.Earlier quoted context omitted.
Anybody that can run sendmail as root (or use an alternate program, or compile their own) can spoof the envelope sender.
Ah, gotcha. You're saying that you sent an email with a valid envelope sender from your domain, with only a spoofed From: address, and gmail sent it back. If so, nice!
How much harder would this attack have been with a fully patched OSX Mavericks target and an Apple Time Capsule router?
I don't know about the vulnerabilities in the Time Capsule router, but from my understanding the only router firmware even remotely worth a look in terms of security would be OpenWRT.
Which one do you think will happen first: This guy goes to jail, or this guy gets a job offer?
Sweet story ... and another vote for MikroTik routers for personal use.
One more reason to use NoScript - it would have made the CSRF significantly harder to pull off. And a reason to use an OS with a proper package manager, of course ;)
Not really. Depending on the protocol CSRFs are often an easy 1-click exploit on noscript-enabled browsers. Something like this: " /> Is the corresponding 1-click that works on noscript.
How much harder would this attack have been with a fully patched OSX Mavericks target and an Apple Time Capsule router?
Well, if his password was weak, easier than TFA. I don't know about the vulnerabilities in the Time Capsule router, but from my understanding the only router firmware even remotely worth a look in terms of security would be OpenWRT.
but I figured I should ask this guy, sounds like he knows what he's doing.
While this is an interesting article and this is certainly feasible, I'm left with the opinion that this is fiction and didn't actually happen.
Everything is feasible except the faked linkedin email - it wouldn't pass SPF and so I'm pretty sure gmail would junk it.