A group of Japanese security enthusiasts has developed a little tool called IE'en which exposes traffic between an IE user and any server he's contacting, including logins and passwords over HTTPS. What's interesting here is the ability to capture packets between the client and server by exploiting DCOM (Distributed Component Object Model), a Microsoft program interface allowing the mediation and exchange of program and data objects over a network, similar to CORBA. According to MS, it "enables software components to communicate directly over a network in a reliable, secure, and efficient manner." Well, reliable and efficient it may be, but 'secure' is clearly a bit of a stretcher.
|