Likes Likes:  0
Resultaten 1 tot 2 van de 2
Geen
  1. #1
    Jay D. Dyson
    Re: Sensitive Information Disclosure Vulnerability in Kinetics Kiosk
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Sensitive Information Disclosure Vulnerability in Kinetics Kiosk

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    On Thu, 18 Aug 2005, Jason Coombs wrote:

    > Furthermore, the use of an IP address that is outside of the RFC 1918
    > private subnet address range appears very irresponsible.


    Especially considering that the IP address is within a Wells Fargo
    Bank class B netblock. It just gets curiouser and curiouser.

    - -Jay

    ( ( _______
    )) )) .-"There's always time for a good cup of coffee"-. >====<--.
    C|~~|C|~~| \----- Jay D. Dyson -- jdyson@treachery.net -----/ | = |-'
    `--' `--' `- Pros built the Titanic; amateurs, the Ark. -' `------'

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.1 (TreacherOS)
    Comment: See http://www.treachery.net/~jdyson/ for current keys.

    iD8DBQFDBNTIxzN3WIW0edsRAuxAAJ9rg3C0L0WJGkQURqEGls SyGqaiZgCeMe8E
    neg0tBh1SQkhiIakZDYdq1I=
    =87Lh
    -----END PGP SIGNATURE-----

  2. #2
    Zow Terry Brugger
    Re: Sensitive Information Disclosure Vulnerability in Kinetics Kiosk
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Sensitive Information Disclosure Vulnerability in Kinetics Kiosk

    > Especially considering that the IP address is within a Wells Fargo
    > Bank class B netblock. It just gets curiouser and curiouser.


    No, that actually explains a lot -- you know how you swipe your credit card
    at the kiosk so that it can retrieve your flight information? Well, it needs
    to map your CC number to a name, and whether your name is encoded on the mag
    stripe or not, it should go back to a bank to retrieve that information. I
    bet you one good cup of coffee (offer applies to Jason and Jay only) that
    that's why they're connecting to Wells Fargo.

    Now then, one could debate the wisdom of transferring this information in the
    clear (http as opposed to https). I'm not going to try to connect to the
    server myself out of politeness, but I would hope that the connection is
    being tunneled through the Internet by a VPN, and that the server is
    otherwise inaccessible. If that is the case, I think the debate over whether
    it uses a public or private IP is academic.

    The potential insecurities in the use of Win/IE for a public kiosk are worth
    considering, however I'm personally more concerned when my pilot tells us
    that we're going to be delayed from pushing back for a minute because they
    need to do the equivalent of a Control-Alt-Delete to the plane.

    Cheers,
    Terry

    import StandardDisclaimer;



Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics