Skip navigation.
 
mlRe: Anybody using Pantomime or mail-core framework?
FROM : Jens Alfke
DATE : Wed May 14 02:48:34 2008

On 13 May '08, at 5:40 PM, Matt Burnett wrote:

> Now your talking about hackers instead of spammers.


There's not really a difference nowadays, since most spam is sent from 
pwned servers/PCs.

> It is hard to sniff a HTTP session, you have to penetrate your 
> victim's network enough to be able to do so.


We're talking about a downloadable app. All I have to do is download a 
copy of it and either sniff its network traffic, or run it in gdb and 
set breakpoints on likely API calls that set up HTTP authentication. 
Then I know the URL and password.

(None of this may be likely, but security requires thinking about the 
worst possible scenarios.)

—Jens

Related mailsAuthorDate
mlAnybody using Pantomime or mail-core framework? vinitha May 12, 13:25
mlRe: Anybody using Pantomime or mail-core framework? Omar Qazi May 13, 07:57
mlRe: Anybody using Pantomime or mail-core framework? Jens Alfke May 13, 08:07
mlRe: Anybody using Pantomime or mail-core framework? Omar Qazi May 13, 08:16
mlRe: Anybody using Pantomime or mail-core framework? Matt Burnett May 14, 01:35
mlRe: Anybody using Pantomime or mail-core framework? Jens Alfke May 14, 01:45
mlRe: Anybody using Pantomime or mail-core framework? Matt Burnett May 14, 02:40
mlRe: Anybody using Pantomime or mail-core framework? Jens Alfke May 14, 02:48
mlRe: Anybody using Pantomime or mail-core framework? Andrew Farmer May 15, 23:17