09.08.2015 Views

More Tricks For Defeating SSL In Practice

More Tricks For Defeating SSL In Practice

More Tricks For Defeating SSL In Practice

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

A Third Cut: ocsp-aware sslsniffsslsniff●Watch network and fingerprints clients for level ofvulnerability.● Every NSS client's communication is intercepted –either with a specific “null termination” certificate, orwith the “universal wildcard” certificate.●●●Every non-NSS client that is vulnerable is interceptedwith a “null termination” certificate if available for thedestination host.Non-vulnerable clients are left alone to avoiddetection.Optionally watch for OCSP requests corresponding tocertificates we're using, and “tryLater” them to defeatOCSP.Moxie Marlinspike<strong>In</strong>stitute <strong>For</strong> Disruptive Studies

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!