<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Multiple vulnerabilities in LogMeIn web interface can be used to control your computer and steal arbitary files</title>
	<atom:link href="http://securethoughts.com/2009/06/multiple-vulnerabilities-in-logmein-web-interface-can-be-used-to-control-your-computer-and-steal-arbitary-files/feed/" rel="self" type="application/rss+xml" />
	<link>http://securethoughts.com/2009/06/multiple-vulnerabilities-in-logmein-web-interface-can-be-used-to-control-your-computer-and-steal-arbitary-files/</link>
	<description>Inferno&#039;s Blog on Application Security</description>
	<lastBuildDate>Fri, 02 Apr 2010 17:28:55 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Web Remote Access Weaknesses with LogMeIn Web Interface &#124;</title>
		<link>http://securethoughts.com/2009/06/multiple-vulnerabilities-in-logmein-web-interface-can-be-used-to-control-your-computer-and-steal-arbitary-files/comment-page-1/#comment-68</link>
		<dc:creator>Web Remote Access Weaknesses with LogMeIn Web Interface &#124;</dc:creator>
		<pubDate>Fri, 05 Jun 2009 15:21:24 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=379#comment-68</guid>
		<description>[...] More info here: http://securethoughts.com/2009/06/multiple-vulnerabilities-in-logmein-web-interface-can-be-used-to-c... [...]</description>
		<content:encoded><![CDATA[<p>[...] More info here: <a href="http://securethoughts.com/2009/06/multiple-vulnerabilities-in-logmein-web-interface-can-be-used-to-c.." rel="nofollow">http://securethoughts.com/2009/06/multiple-vulnerabilities-in-logmein-web-interface-can-be-used-to-c..</a>. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Trip Kucera</title>
		<link>http://securethoughts.com/2009/06/multiple-vulnerabilities-in-logmein-web-interface-can-be-used-to-control-your-computer-and-steal-arbitary-files/comment-page-1/#comment-67</link>
		<dc:creator>Trip Kucera</dc:creator>
		<pubDate>Fri, 05 Jun 2009 13:02:13 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=379#comment-67</guid>
		<description>LogMeIn is aware of this advisory and the issues raised here are scheduled to be addressed in the next release of the LogMeIn host software, currently slated for availability in Summer 2009.

These findings are un-exploitable under most circumstances. Remote logins (such as logins to a computer via logmein.com, a desktop shortcut or a LogMeIn RSS feed) are safe from cross-site request forgery (CSRF) exploits since the hostname is randomized during remote access. A typical remote URL would appear as https://dudley-wlibwwlcqq.app107.logmein.com/, which is not possible for an attacker to anticipate. To exploit one of the reported findings a user would have to visit a malicious website while being logged in to a local LogMeIn installation as an administrator via the https://localhost:2002 interface. 

Users are only at risk from malicious websites when they have the local LogMeIn web interface opened and they’re logged in with administrator credentials – this is typically done by opening a browser and manually pointing it at https://localhost:2002 or by clicking the LogMeIn tray icon and selecting Open LogMeIn from the menu. The only reason a user would do this is to change LogMeIn host configuration settings. 

LogMeIn recommends one of the following:

- Before opening the local web interface, users should close all other browser windows and tabs. When finished with the local LogMeIn interface, users should click Log Out or Disconnect.

- If the above is not feasible, do not access the local web interface. All settings and options available from the local web interface are also available via logins through the logmein.com website, and that is not at risk from CSRF.

Thank you,
Trip Kucera
Director, Corporate Communications
LogMeIn, Inc.</description>
		<content:encoded><![CDATA[<p>LogMeIn is aware of this advisory and the issues raised here are scheduled to be addressed in the next release of the LogMeIn host software, currently slated for availability in Summer 2009.</p>
<p>These findings are un-exploitable under most circumstances. Remote logins (such as logins to a computer via logmein.com, a desktop shortcut or a LogMeIn RSS feed) are safe from cross-site request forgery (CSRF) exploits since the hostname is randomized during remote access. A typical remote URL would appear as <a href="https://dudley-wlibwwlcqq.app107.logmein.com/" rel="nofollow">https://dudley-wlibwwlcqq.app107.logmein.com/</a>, which is not possible for an attacker to anticipate. To exploit one of the reported findings a user would have to visit a malicious website while being logged in to a local LogMeIn installation as an administrator via the <a href="https://localhost:2002" rel="nofollow">https://localhost:2002</a> interface. </p>
<p>Users are only at risk from malicious websites when they have the local LogMeIn web interface opened and they’re logged in with administrator credentials – this is typically done by opening a browser and manually pointing it at <a href="https://localhost:2002" rel="nofollow">https://localhost:2002</a> or by clicking the LogMeIn tray icon and selecting Open LogMeIn from the menu. The only reason a user would do this is to change LogMeIn host configuration settings. </p>
<p>LogMeIn recommends one of the following:</p>
<p>- Before opening the local web interface, users should close all other browser windows and tabs. When finished with the local LogMeIn interface, users should click Log Out or Disconnect.</p>
<p>- If the above is not feasible, do not access the local web interface. All settings and options available from the local web interface are also available via logins through the logmein.com website, and that is not at risk from CSRF.</p>
<p>Thank you,<br />
Trip Kucera<br />
Director, Corporate Communications<br />
LogMeIn, Inc.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Inferno</title>
		<link>http://securethoughts.com/2009/06/multiple-vulnerabilities-in-logmein-web-interface-can-be-used-to-control-your-computer-and-steal-arbitary-files/comment-page-1/#comment-65</link>
		<dc:creator>Inferno</dc:creator>
		<pubDate>Thu, 04 Jun 2009 09:45:24 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=379#comment-65</guid>
		<description>@LightOS, Anarchy, David - thanks for your feedback...</description>
		<content:encoded><![CDATA[<p>@LightOS, Anarchy, David &#8211; thanks for your feedback&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LightOS</title>
		<link>http://securethoughts.com/2009/06/multiple-vulnerabilities-in-logmein-web-interface-can-be-used-to-control-your-computer-and-steal-arbitary-files/comment-page-1/#comment-63</link>
		<dc:creator>LightOS</dc:creator>
		<pubDate>Thu, 04 Jun 2009 00:26:44 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=379#comment-63</guid>
		<description>Impressed once again, keep them coming!</description>
		<content:encoded><![CDATA[<p>Impressed once again, keep them coming!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David</title>
		<link>http://securethoughts.com/2009/06/multiple-vulnerabilities-in-logmein-web-interface-can-be-used-to-control-your-computer-and-steal-arbitary-files/comment-page-1/#comment-62</link>
		<dc:creator>David</dc:creator>
		<pubDate>Wed, 03 Jun 2009 18:22:43 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=379#comment-62</guid>
		<description>Lot&#039;s of IT companies use it for fixing clients problems by remote, so this is a huge leak in my opinion. Hope Logmein they fix this soon.

Nice work</description>
		<content:encoded><![CDATA[<p>Lot&#8217;s of IT companies use it for fixing clients problems by remote, so this is a huge leak in my opinion. Hope Logmein they fix this soon.</p>
<p>Nice work</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anarchy Angel</title>
		<link>http://securethoughts.com/2009/06/multiple-vulnerabilities-in-logmein-web-interface-can-be-used-to-control-your-computer-and-steal-arbitary-files/comment-page-1/#comment-61</link>
		<dc:creator>Anarchy Angel</dc:creator>
		<pubDate>Wed, 03 Jun 2009 14:33:52 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=379#comment-61</guid>
		<description>great work! thanx for sharing.</description>
		<content:encoded><![CDATA[<p>great work! thanx for sharing.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

