09.08.2015 Views

More Tricks For Defeating SSL In Practice

More Tricks For Defeating SSL In Practice

More Tricks For Defeating SSL In Practice

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Postscript:Stripping NULL is no solution●●●●So if we register a domain like sitekey.baWe can get a certificate forsitekey.ba\0nkofamerica.comThe CAs that are internally vulnerable to thisattack will validate that certificate againstsitekey.ba, which we own.When the cert is later presented to a <strong>SSL</strong>implementation that strips \0, the certificate'scommon name becomes:sitekey.bankofamerica.comMoxie Marlinspike<strong>In</strong>stitute <strong>For</strong> Disruptive Studies

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!