- To: SLUG-CHAT <slug-chat@xxxxxxxxxxx>
- Subject: [chat] "Steal" data before encryption
- From: Phil Scarratt <fil@xxxxxxxxxxx>
- Date: Thu, 10 Jul 2003 22:07:08 +1000
- Organization: Draxsen Technologies
- User-agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.0.1) Gecko/20020823 Netscape/7.0
Hi All
Member of main list for awhile ... new to slug chat...
...is it possible (however unlikely or difficult it might be - or even
pointless due to other easier methods of doing effectively the same
thing) for a hacker/attacker to get access to data entered into a form
in a browser on an SSL connection to a remote server BEFORE it is
encrypted but after the form submit has been clicked - so I guess what I
am really asking is when/where does the encryption occur (I presume the
browser does it) and is it possible to get at the data via some
"backdoor" before encryption?????
or I guess this is really a browser vulnerability question...
I know keystroke loggers exist and presumably the data must exist in
memory at some stage so looking at the memory might work...just a
hypothetical question really which came about from some research into
securing web apps that I am doing.
--
Phil Scarratt