<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Dynamic Linking: ELF vs. Mach-O</title>
	<atom:link href="http://timetobleed.com/dynamic-linking-elf-vs-mach-o/feed/" rel="self" type="application/rss+xml" />
	<link>http://timetobleed.com/dynamic-linking-elf-vs-mach-o/</link>
	<description>technical ramblings from a wanna-be unix dinosaur</description>
	<lastBuildDate>Thu, 05 Jan 2012 16:28:11 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Dynamic symbol table duel: ELF vs Mach-O, round 2 at time to bleed by Joe Damato</title>
		<link>http://timetobleed.com/dynamic-linking-elf-vs-mach-o/comment-page-1/#comment-711</link>
		<dc:creator>Dynamic symbol table duel: ELF vs Mach-O, round 2 at time to bleed by Joe Damato</dc:creator>
		<pubDate>Tue, 01 Jun 2010 13:02:46 +0000</pubDate>
		<guid isPermaLink="false">http://timetobleed.com/?p=1613#comment-711</guid>
		<description>[...] The intention of this post is to continue highlighting some of the similarities and differences between ELF and Mach-O that I encountered while building memprof. The previous post in this series can be found here. [...]</description>
		<content:encoded><![CDATA[<p>[...] The intention of this post is to continue highlighting some of the similarities and differences between ELF and Mach-O that I encountered while building memprof. The previous post in this series can be found here. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Florin Andrei</title>
		<link>http://timetobleed.com/dynamic-linking-elf-vs-mach-o/comment-page-1/#comment-669</link>
		<dc:creator>Florin Andrei</dc:creator>
		<pubDate>Thu, 27 May 2010 07:05:08 +0000</pubDate>
		<guid isPermaLink="false">http://timetobleed.com/?p=1613#comment-669</guid>
		<description>That  explains the otherwise unexplainable &quot;event&quot; last year, when we had our AmEx card hijacked during a trip to Eastern Europe. All they needed was one attempt to login to the AmEx site.</description>
		<content:encoded><![CDATA[<p>That  explains the otherwise unexplainable &#8220;event&#8221; last year, when we had our AmEx card hijacked during a trip to Eastern Europe. All they needed was one attempt to login to the AmEx site.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vojislav Stojkovic</title>
		<link>http://timetobleed.com/dynamic-linking-elf-vs-mach-o/comment-page-1/#comment-660</link>
		<dc:creator>Vojislav Stojkovic</dc:creator>
		<pubDate>Wed, 26 May 2010 19:12:30 +0000</pubDate>
		<guid isPermaLink="false">http://timetobleed.com/?p=1613#comment-660</guid>
		<description>You&#039;re all heart, Brad. Let&#039;s see, your contribution was to flame me and then add nothing useful to what I said.&lt;br&gt;&lt;br&gt;I&#039;m not going to discuss my personal shopping and banking habits with you, or the security precautions I might take under either normal or exceptional circumstances. I will, however, point out why your reply was a completely useless flame: if a public location is not safe due to factors that have to do with the customer or the location itself, it&#039;s not an excuse for a bank or a merchant to fail at their end of the security. That&#039;s what we were all criticizing here, in case you forgot.</description>
		<content:encoded><![CDATA[<p>You&#39;re all heart, Brad. Let&#39;s see, your contribution was to flame me and then add nothing useful to what I said.</p>
<p>I&#39;m not going to discuss my personal shopping and banking habits with you, or the security precautions I might take under either normal or exceptional circumstances. I will, however, point out why your reply was a completely useless flame: if a public location is not safe due to factors that have to do with the customer or the location itself, it&#39;s not an excuse for a bank or a merchant to fail at their end of the security. That&#39;s what we were all criticizing here, in case you forgot.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sergey Shepelev</title>
		<link>http://timetobleed.com/dynamic-linking-elf-vs-mach-o/comment-page-1/#comment-658</link>
		<dc:creator>Sergey Shepelev</dc:creator>
		<pubDate>Wed, 26 May 2010 18:01:07 +0000</pubDate>
		<guid isPermaLink="false">http://timetobleed.com/?p=1613#comment-658</guid>
		<description>Sure, SSL is easy and why not. Probably, it&#039;s just much less important for me than for you. My intent was rather sarcastic, not trolling actually.</description>
		<content:encoded><![CDATA[<p>Sure, SSL is easy and why not. Probably, it&#39;s just much less important for me than for you. My intent was rather sarcastic, not trolling actually.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Website Design</title>
		<link>http://timetobleed.com/dynamic-linking-elf-vs-mach-o/comment-page-1/#comment-655</link>
		<dc:creator>Website Design</dc:creator>
		<pubDate>Wed, 26 May 2010 17:13:12 +0000</pubDate>
		<guid isPermaLink="false">http://timetobleed.com/?p=1613#comment-655</guid>
		<description>Wow... that&#039;s amazing!  What a screw up, somebody is getting fired...</description>
		<content:encoded><![CDATA[<p>Wow&#8230; that&#39;s amazing!  What a screw up, somebody is getting fired&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: skhan</title>
		<link>http://timetobleed.com/dynamic-linking-elf-vs-mach-o/comment-page-1/#comment-644</link>
		<dc:creator>skhan</dc:creator>
		<pubDate>Wed, 26 May 2010 08:16:56 +0000</pubDate>
		<guid isPermaLink="false">http://timetobleed.com/?p=1613#comment-644</guid>
		<description>This is the cost of outsourcing...I could care less what they say!</description>
		<content:encoded><![CDATA[<p>This is the cost of outsourcing&#8230;I could care less what they say!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sswam</title>
		<link>http://timetobleed.com/dynamic-linking-elf-vs-mach-o/comment-page-1/#comment-645</link>
		<dc:creator>sswam</dc:creator>
		<pubDate>Wed, 26 May 2010 07:22:19 +0000</pubDate>
		<guid isPermaLink="false">http://timetobleed.com/?p=1613#comment-645</guid>
		<description>given that AMEX and other credit card companies (usury companies) steal your money as fast as they can, why should they care if other people steal it too?  They still make their cut when someone steals your money.</description>
		<content:encoded><![CDATA[<p>given that AMEX and other credit card companies (usury companies) steal your money as fast as they can, why should they care if other people steal it too?  They still make their cut when someone steals your money.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jason</title>
		<link>http://timetobleed.com/dynamic-linking-elf-vs-mach-o/comment-page-1/#comment-646</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Wed, 26 May 2010 06:39:29 +0000</pubDate>
		<guid isPermaLink="false">http://timetobleed.com/?p=1613#comment-646</guid>
		<description>Great point, seems like just a temporary &quot;technical&quot; fix rather than a comprehensive solution.&lt;br&gt;&lt;br&gt;If I don&#039;t see that lock up there and special treatment of the url box, I&#039;m not putting in my CC info. Even then, I&#039;m fairly certain that if they have the page and the iframe on HTTPS, those 3rd party scripts can then access all the data in the iframe. Ironic that adding HTTPS to the parent page reduces security!</description>
		<content:encoded><![CDATA[<p>Great point, seems like just a temporary &#8220;technical&#8221; fix rather than a comprehensive solution.</p>
<p>If I don&#39;t see that lock up there and special treatment of the url box, I&#39;m not putting in my CC info. Even then, I&#39;m fairly certain that if they have the page and the iframe on HTTPS, those 3rd party scripts can then access all the data in the iframe. Ironic that adding HTTPS to the parent page reduces security!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: George</title>
		<link>http://timetobleed.com/dynamic-linking-elf-vs-mach-o/comment-page-1/#comment-637</link>
		<dc:creator>George</dc:creator>
		<pubDate>Wed, 26 May 2010 06:08:06 +0000</pubDate>
		<guid isPermaLink="false">http://timetobleed.com/?p=1613#comment-637</guid>
		<description>The unfortunate thing is that iframe jails do very little to secure anything &amp; the fact that the form now submits via HTTPS means nothing so long as the page loaded via HTTP.  How would my mom for instance know it&#039;s safe to provide her card information since there&#039;s no https: and lock for her to check?  Should she fire up Wireshark and do a test transaction?  LOL!&lt;br&gt;&lt;br&gt;It gets worse.  In the &quot;old days&quot; of http based MitM it took a skilled person to do anything more than sniff the connection.  Now days there are plenty of freely available packages, including some &quot;point and click&quot; ones that allow attackers to insert their own markup and scripts into a an HTTP delivered page to then deliver whatever they&#039;d like. &lt;br&gt;&lt;br&gt;The only way for AMEX to fix this is to turn the entire site to HTTPS &amp; stop loading third-party JavaScript which they have zero control over.</description>
		<content:encoded><![CDATA[<p>The unfortunate thing is that iframe jails do very little to secure anything &#038; the fact that the form now submits via HTTPS means nothing so long as the page loaded via HTTP.  How would my mom for instance know it&#39;s safe to provide her card information since there&#39;s no https: and lock for her to check?  Should she fire up Wireshark and do a test transaction?  LOL!</p>
<p>It gets worse.  In the &#8220;old days&#8221; of http based MitM it took a skilled person to do anything more than sniff the connection.  Now days there are plenty of freely available packages, including some &#8220;point and click&#8221; ones that allow attackers to insert their own markup and scripts into a an HTTP delivered page to then deliver whatever they&#39;d like. </p>
<p>The only way for AMEX to fix this is to turn the entire site to HTTPS &#038; stop loading third-party JavaScript which they have zero control over.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joe Damato (ice799)</title>
		<link>http://timetobleed.com/dynamic-linking-elf-vs-mach-o/comment-page-1/#comment-635</link>
		<dc:creator>Joe Damato (ice799)</dc:creator>
		<pubDate>Wed, 26 May 2010 05:34:18 +0000</pubDate>
		<guid isPermaLink="false">http://timetobleed.com/?p=1613#comment-635</guid>
		<description>wireshark output is proof that the post went back over cleartext.</description>
		<content:encoded><![CDATA[<p>wireshark output is proof that the post went back over cleartext.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

