Re: [White Paper] The easiest way to get around SSL
"Keith W. McCammon" <[email protected]> Tue, 16 Sep 2003 13:20:42 -0400
| Newsgroups | gmane.comp.security.papers |
|---|---|
| Message-ID | <[email protected]> |
How does the application "impersonate" the digital certificate presented=20 to the client by the server? I fail to understand how a successful=20 impersonation could take place, given the information presented in your=20 paper. Roberto Larcher wrote: > [Title] > The easiest way to get around SSL >=20 > [Abstract] >=20 > This paper explains how it is often possible, with the simple > substitution of a string, to get around a =93secure=94 > implementation based on an incorrect use of SSL. > Please note that this document does not contain any information > about weaknesses of the SSL protocol; it simply shows the easiest > way to get around the correct functioning of the SSL protocol. > In this document typical =93weakly secure=94 implementation based on > the SSL protocol are illustrated. > A simple test application is also proposed to check if existing > implementations are indeed =93weakly secure=94. > This document has an informative purpose. >=20 > [Links] > English version > http://webteca.altervista.org/download/download4.php?get=3Dwp_https2htt= p_en >=20 > Italian version > http://webteca.altervista.org/download/download4.php?get=3Dwp_https2htt= p_it >=20 >=20 > [Contact Information] >=20 > ing. Roberto Larcher >=20 > robertolarcher (at) hotmail.com > http://webteca.altervista.org >=20 > _________________________________________________________________ > Personalizza MSN Messenger con sfondi e fotografie!=20 > http://www.ilovemessenger.msn.it/