Bugtraq mailing list archives

Microsoft ClickOnce MITM Vulnerabilities


From: Tom Ritter <tom () ritter vg>
Date: Sat, 17 Jul 2010 11:30:52 -0400

ClickOnce is a Microsoft technology intended to make deployment of
desktop applications extremely simple.  When deployed over HTTP, it is
vulnerable to several types of Man in the Middle attacks; despite the
ability to sign the executables.  See attached.

-tom

Attachment: ClickOnce-MITM.txt
Description:


Current thread: