Re: [White Paper] The easiest way to get around SSL

"Keith W. McCammon" <[email protected]> Tue, 16 Sep 2003 13:20:42 -0400
Newsgroups gmane.comp.security.papers
Message-ID <[email protected]>
How does the application "impersonate" the digital certificate presented=20
to the client by the server?  I fail to understand how a successful=20
impersonation could take place, given the information presented in your=20
paper.

Roberto Larcher wrote:
> [Title]
> The easiest way to get around SSL
>=20
> [Abstract]
>=20
> This paper explains how it is often possible, with the simple
> substitution of a string, to get around a =93secure=94
> implementation based on an incorrect use of SSL.
> Please note that this document does not contain any information
> about weaknesses of the SSL protocol; it simply shows the easiest
> way to get around the correct functioning of the SSL protocol.
> In this document typical =93weakly secure=94 implementation based on
> the SSL protocol are illustrated.
> A simple test application is also proposed to check if existing
> implementations are indeed =93weakly secure=94.
> This document has an informative purpose.
>=20
> [Links]
> English version
> http://webteca.altervista.org/download/download4.php?get=3Dwp_https2htt=
p_en
>=20
> Italian version
> http://webteca.altervista.org/download/download4.php?get=3Dwp_https2htt=
p_it
>=20
>=20
> [Contact Information]
>=20
> ing. Roberto Larcher
>=20
> robertolarcher (at) hotmail.com
> http://webteca.altervista.org
>=20
> _________________________________________________________________
> Personalizza MSN Messenger con sfondi e fotografie!=20
> http://www.ilovemessenger.msn.it/