Collected research
Hacking without 0days: Drive-by Java
Hacking without 0days Drive-by Java
A cryptographically signed Java applet gets full desktop privileges from the browser once the user clicks through one dialog, with no vulnerability involved. pdp argues the applet name and certificate CN can be forged to make the prompt look legitimate, giving roughly a coin-flip success rate, and that this beats signed JavaScript, browser extensions or a downloaded executable for reliability.
Record
- Document
- Hacking without 0days Drive-by Java
- Researcher
- pdp
- Published by
- gnucitizen.org
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of pdp, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .