Re: ? Unsafe terminal escape sequences and ANSI codes from decryption
Grant Taylor <[email protected]> Mon, 6 Mar 2023 18:19:24 -0700
| Newsgroups | sci.crypt,alt.security.pgp,alt.bbs,comp.terminals,alt.computer.security |
|---|---|
| Organization | TNet Consulting |
| Message-ID | <[email protected]> |
On 3/6/23 5:35 PM, Dennis Boone wrote: > I'm pretty sure I've seen terminals where you can set it remotely, > but I can't point to evidence off the top. ACK > But that's just one scenario. Aggravating factors might include: > > - Even if you can't load answerback, you might be able to load > programmable function keys, and then entice the user to press one. > > - The emulation of VT100 or similar gives one of the most powerful > command sets. Fair enough. I think the other big thing that I'm struggling with is the fact that in a nominally two party system, the host and the terminal (emulator), the host would be making the terminal (emulator) attack the host. And nominally be enticing the user of the terminal (emulator) to take action. With this in mind, I'm not seeing the actual attack vector / scenario. Could things be done, maybe. But what would it accomplish that the host didn't already have? -- Grant. . . . unix || die