Project

General

Profile

Feature #83

Client hijacking in activation

Added by Tobias Wich almost 7 years ago. Updated over 3 years ago.

Status:
New
Priority:
Low
Assignee:
-
Target version:
Start date:
05/22/2012
Due date:
% Done:

0%

Estimated time:
24.00 h
Reviewer:
Build Version:

Description

Prevent the localhost connection from being triggered by a foreign user/ session. Perhaps an X session.
Need to evaluate attack vector first

History

#1 Updated by Tobias Wich about 6 years ago

  • Target version deleted (4)

#2 Updated by Andreas Kuckartz about 6 years ago

  • Priority changed from Normal to High

#3 Updated by Tobias Wich almost 5 years ago

  • Target version set to 1.3.0

A "desktop firewall" asking the user whether to accept connections from a certain agent has been proposed.

As of now, it's unclear how to detect the agent and whether the grant should be permanent or per session/ limited amount of time.

#4 Updated by Tobias Wich over 3 years ago

  • Tracker changed from Bug to Feature
  • Priority changed from High to Low

Also available in: Atom PDF