TimeDoctor Pro 1.4.72.3 Insecure Transport

Discussion in 'News Aggregator' started by Packet Storm, 1 Jul 2015.

  1. Packet Storm

    Packet Storm Guest

    TimeDoctor autoupdate feature downloads and executes files over plain HTTP and doesn't perform any check with the files. An attacker with MITM capabilities (i.e., when user connects to a public wifi) could override the Timedoctor subdomain and then execute custom binaries on the machine where the application is running.

    Continue reading...
     

Share This Page

Loading...