~/.hosts patch
Luigi Rizzo
rizzo at icir.org
Wed Jun 21 07:02:54 UTC 2006
On Wed, Jun 21, 2006 at 06:38:16AM +0000, John Birrell wrote:
> On Wed, Jun 21, 2006 at 08:31:36AM +0200, Harti Brandt wrote:
> > Wouldn't this enable the same kind of phishing attacks there are under
> > windows? As far as I remember there are attacks where the hosts file
> > (don't remember how its called under windows) is rewriten by a virus/java
> > script/whatever to contain a different IP address for a given hostname?
> > Suppose someone fakes the website of www.foobank.com, then manages to
> > insert www.foobank.com with the wrong IP address into ~/.hosts?
>
> Ugh. Now that is a scary thought.
and that's why people use https and certificates!
what's the concern here ?
luigi
More information about the freebsd-current
mailing list