Tugger the SLUGger!SLUG Mailing List Archives

[chat] "Steal" data before encryption


Hi All

Member of main list for awhile ... new to slug chat...

...is it possible (however unlikely or difficult it might be - or even pointless due to other easier methods of doing effectively the same thing) for a hacker/attacker to get access to data entered into a form in a browser on an SSL connection to a remote server BEFORE it is encrypted but after the form submit has been clicked - so I guess what I am really asking is when/where does the encryption occur (I presume the browser does it) and is it possible to get at the data via some "backdoor" before encryption?????

or I guess this is really a browser vulnerability question...

I know keystroke loggers exist and presumably the data must exist in memory at some stage so looking at the memory might work...just a hypothetical question really which came about from some research into securing web apps that I am doing.


--
Phil Scarratt