websecurity@lists.webappsec.org

The Web Security Mailing List

View all threads

The "localhosed" attack

AK
Amit Klein
Mon, Jun 22, 2015 2:34 PM

Hi

I know that normally this list doesn't discuss vendor/product-specific
vulnerabilities, but this one is quite amusing and I think people can
learn from it (I sure did...).

So enjoy:

http://www.securitygalore.com/site3/localhosed

BTW Microsoft opted not to fix it.

Thanks,
-Amit
http://www.securitygalore.com/

Hi I know that normally this list doesn't discuss vendor/product-specific vulnerabilities, but this one is quite amusing and I think people can learn from it (I sure did...). So enjoy: http://www.securitygalore.com/site3/localhosed BTW Microsoft opted not to fix it. Thanks, -Amit http://www.securitygalore.com/
RA
Robert A.
Mon, Jun 22, 2015 11:32 PM

The list has missed your research Amit! :)

  • Robert A.

On Mon, 22 Jun 2015, Amit Klein wrote:

Hi

I know that normally this list doesn't discuss vendor/product-specific
vulnerabilities, but this one is quite amusing and I think people can
learn from it (I sure did...).

So enjoy:

http://www.securitygalore.com/site3/localhosed

BTW Microsoft opted not to fix it.

Thanks,
-Amit
http://www.securitygalore.com/


The Web Security Mailing List

WebSecurity RSS Feed
http://www.webappsec.org/rss/websecurity.rss

Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA

WASC on Twitter
http://twitter.com/wascupdates

websecurity@lists.webappsec.org
http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org

The list has missed your research Amit! :) - Robert A. On Mon, 22 Jun 2015, Amit Klein wrote: > Hi > > I know that normally this list doesn't discuss vendor/product-specific > vulnerabilities, but this one is quite amusing and I think people can > learn from it (I sure did...). > > So enjoy: > > http://www.securitygalore.com/site3/localhosed > > BTW Microsoft opted not to fix it. > > Thanks, > -Amit > http://www.securitygalore.com/ > > _______________________________________________ > The Web Security Mailing List > > WebSecurity RSS Feed > http://www.webappsec.org/rss/websecurity.rss > > Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA > > WASC on Twitter > http://twitter.com/wascupdates > > websecurity@lists.webappsec.org > http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org >
SO
Segal, Ory
Sun, Jun 28, 2015 7:44 AM

+1 on that!


Ory Segal
Director of Threat Research, Cloud Security
Akamai
Mobile: +972-54-773-9359
Email: orsegal@akamai.commailto:orsegal@akamai.com
Twitter: @orysegal

From: "Robert A." <robert@webappsec.orgmailto:robert@webappsec.org>
Date: Tuesday, June 23, 2015 at 2:32 AM
To: Amit Klein <aksecurity@gmail.commailto:aksecurity@gmail.com>
Cc: "websecurity@webappsec.orgmailto:websecurity@webappsec.org" <websecurity@webappsec.orgmailto:websecurity@webappsec.org>
Subject: Re: [WEB SECURITY] The "localhosed" attack

The list has missed your research Amit! :)

  • Robert A.

On Mon, 22 Jun 2015, Amit Klein wrote:

Hi

I know that normally this list doesn't discuss vendor/product-specific
vulnerabilities, but this one is quite amusing and I think people can
learn from it (I sure did...).

So enjoy:

http://www.securitygalore.com/site3/localhosed

BTW Microsoft opted not to fix it.

Thanks,
-Amit
http://www.securitygalore.com/


The Web Security Mailing List

WebSecurity RSS Feed
http://www.webappsec.org/rss/websecurity.rss

Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA

WASC on Twitter
http://twitter.com/wascupdates

websecurity@lists.webappsec.orgmailto:websecurity@lists.webappsec.org
http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org


The Web Security Mailing List

WebSecurity RSS Feed
http://www.webappsec.org/rss/websecurity.rss

Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA

WASC on Twitter
http://twitter.com/wascupdates

websecurity@lists.webappsec.orgmailto:websecurity@lists.webappsec.org
http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org

+1 on that! ---------------------------------------------------- Ory Segal Director of Threat Research, Cloud Security Akamai Mobile: +972-54-773-9359 Email: orsegal@akamai.com<mailto:orsegal@akamai.com> Twitter: @orysegal From: "Robert A." <robert@webappsec.org<mailto:robert@webappsec.org>> Date: Tuesday, June 23, 2015 at 2:32 AM To: Amit Klein <aksecurity@gmail.com<mailto:aksecurity@gmail.com>> Cc: "websecurity@webappsec.org<mailto:websecurity@webappsec.org>" <websecurity@webappsec.org<mailto:websecurity@webappsec.org>> Subject: Re: [WEB SECURITY] The "localhosed" attack The list has missed your research Amit! :) - Robert A. On Mon, 22 Jun 2015, Amit Klein wrote: Hi I know that normally this list doesn't discuss vendor/product-specific vulnerabilities, but this one is quite amusing and I think people can learn from it (I sure did...). So enjoy: http://www.securitygalore.com/site3/localhosed BTW Microsoft opted not to fix it. Thanks, -Amit http://www.securitygalore.com/ _______________________________________________ The Web Security Mailing List WebSecurity RSS Feed http://www.webappsec.org/rss/websecurity.rss Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA WASC on Twitter http://twitter.com/wascupdates websecurity@lists.webappsec.org<mailto:websecurity@lists.webappsec.org> http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org _______________________________________________ The Web Security Mailing List WebSecurity RSS Feed http://www.webappsec.org/rss/websecurity.rss Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA WASC on Twitter http://twitter.com/wascupdates websecurity@lists.webappsec.org<mailto:websecurity@lists.webappsec.org> http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org