由买买提看人间百态

boards

本页内容为未名空间相应帖子的节选和存档,一周内的贴子最多显示50字,超过一周显示500字 访问原贴
PDA版 - 云存储都是垃圾
相关主题
nokia 手机怎么收HOTMAIL软软打脸了
为何gmail收不了office 365 mail?别吵了masterkey的app有了
Amazon也出drive了,这世界真jb热闹Adroid版的微信的安全问题
Blackberry的 软件很多 无法 破解 啊现在win7 PC占有率50.1%, win8:12,6%
Tomtom变砖了,地图怎么更新啊MS Surface Has Lost An Estimated $1.7 Billion Since Debut
touchpad中的patch不能升级、删除Xbox One 4亿亏损,Surface 17亿亏损
OpenOffice悲剧了Researchers hack Gmail app with 92% success rate
Win8普及速度不及Vista:面临平板挑战软软又在犯贱啊
相关话题的讨论汇总
话题: dropbox话题: techniques话题: developers话题: ssl
进入PDA版参与讨论
1 (共1页)
p*******m
发帖数: 20761
1
Developers hack Dropbox, show how to access user data
The cloud storage provider's two-factor authentication was bypassed to gain
access to user data
By Lucas Mearian, Computerworld
August 28, 2013 03:05 PM ET
Add a comment Print
inShare
Computerworld - Two developers have cracked Dropbox's security, even
intercepting SSL data from its servers and bypassing the cloud storage
provider's two-factor authentication, according to a paper they published at
USENIX 2013.
"These techniques are generic enough and we believe would aid in future
software development, testing and security research," the paper says in its
abstract.
[KICK OFF: How Tech is Transforming the NFL]
Dropbox, which claims more than 100 million users upload more than a billion
files daily, said the research didn't actually represent a vulnerability in
its servers.
"We appreciate the contributions of these researchers and everyone who helps
keep Dropbox safe," a spokesperson said in an email reply to Computerworld.
"In the case outlined here, the user's computer would first need to have
been compromised in such a way that it would leave the entire computer, not
just the user's Dropbox, open to attacks across the board."
The two developers, Dhiru Kholia, with the Openwall open source project ,
and Przemyslaw Wegrzyn, with CodePainters, said they reverse-engineered
Dropbox, an application written in Python.
"Our work reveals the internal API used by Dropbox client and makes it
straightforward to write a portable open-source Dropbox client," the paper
states. "Additionally, we show how to bypass Dropbox's two-factor
authentication and gain access to users' data."
The paper presents "new and generic techniques to reverse engineer frozen
Python applications, which are not limited to just the Dropbox world," the
developers wrote.
The researchers described in detail how they were able to unpack, decrypt
and decompile Dropbox from scratch. And, once someone has de-compiled its
source code, how "it is possible to study how Dropbox works in detail.
"We describe a method to bypass Dropbox's two-factor authentication and
hijack Dropbox accounts. Additionally, generic techniques to intercept SSL
data using code injection techniques and monkey patching are presented," the
developers wrote in the paper.
The process they used included various code injection techniques and monkey-
patching to intercept SSL data in a Dropbox client. They also used the
techniques successfully to snoop on SSL data in other commercial products as
well, they said.
The developers are hoping their white hat hacking prompts Dropbox to open
source its platform so that it is no longer a "black box."
"We hope that our work inspires the security community to write an open-
source Dropbox client, rene the techniques presented in this paper and
conduct research into other cloud-based storage systems," they said.
Lucas Mearian covers storage, disaster recovery and business continuity,
financial services infrastructure and health care IT for Computerworld.
Follow Lucas on Twitter at @lucasmearian or subscribe to Lucas's RSS feed.
His e-mail address is l******[email protected].
m**x
发帖数: 245
2
有BUG很正常

gain
at

【在 p*******m 的大作中提到】
: Developers hack Dropbox, show how to access user data
: The cloud storage provider's two-factor authentication was bypassed to gain
: access to user data
: By Lucas Mearian, Computerworld
: August 28, 2013 03:05 PM ET
: Add a comment Print
: inShare
: Computerworld - Two developers have cracked Dropbox's security, even
: intercepting SSL data from its servers and bypassing the cloud storage
: provider's two-factor authentication, according to a paper they published at

1 (共1页)
进入PDA版参与讨论
相关主题
软软又在犯贱啊Tomtom变砖了,地图怎么更新啊
n97 mini $400+tax如何?touchpad中的patch不能升级、删除
TomatoUSB VPN如何搞?OpenOffice悲剧了
后知后觉啊,突然发现android可以直接支持exchangeWin8普及速度不及Vista:面临平板挑战
nokia 手机怎么收HOTMAIL软软打脸了
为何gmail收不了office 365 mail?别吵了masterkey的app有了
Amazon也出drive了,这世界真jb热闹Adroid版的微信的安全问题
Blackberry的 软件很多 无法 破解 啊现在win7 PC占有率50.1%, win8:12,6%
相关话题的讨论汇总
话题: dropbox话题: techniques话题: developers话题: ssl