09.08.2015 Views

More Tricks For Defeating SSL In Practice

More Tricks For Defeating SSL In Practice

More Tricks For Defeating SSL In Practice

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

A Fourth Cut: update-aware sslsniffsslsniff●●●●●●Watch network and fingerprints clients for level ofvulnerability.Every NSS client's communication is intercepted – eitherwith a specific “null prefix” certificate, or with the “universalwildcard” certificate.Every non-NSS client that is vulnerable is intercepted with a“null prefix” certificate if available for the destination host.Non-vulnerable clients are left alone to avoid detection.Optionally watch for OCSP requests corresponding tocertificates we're using, and “tryLater” them to defeat OCSP.Optionally watch for Firefox/Thunderbird update polls, andrespond with a “custom” build.Moxie Marlinspike<strong>In</strong>stitute <strong>For</strong> Disruptive Studies

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!