09.08.2015 Views

More Tricks For Defeating SSL In Practice

More Tricks For Defeating SSL In Practice

More Tricks For Defeating SSL In Practice

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Postscript:Stripping NULL is no solution●●These implementations are vulnerable to avariation of our attack.The key is that some Certificate Authorities arevulnerable to this attack internally.●●When presented withwww.paypal.com\0.thoughtcrime.org, some CAsinternally validate it as www.paypal.comBut the whole string(www.paypal.com\0.thoughtcrime.org) is what endsup in the subject of the cert they later issue.Moxie Marlinspike<strong>In</strong>stitute <strong>For</strong> Disruptive Studies

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!