Hello, today is: 7 September, 2010

Null-Prefix SSL Atttacks Enabled In New Sslsniff

An anonymous reader writes "Moxie Marlinspike, who recently published new attacks on SSL at Defcon 17, seems to have released the new version of sslsniff which supports these attacks. While the release appears to coincide with a patch from Mozilla, every product that uses the Microsoft CryptoAPI is still vulnerable, including Internet Explorer and Outlook. The new version of sslsniff also supports built-in modes for hijacking software auto-updates that depend on SSL, and apparently includes techniques for defeating OCSP as well — making the elimination of existing null-prefix certificates difficult."

Read more of this story at Slashdot.



Vote Result
----------
Score: 0.0, Votes: 0

ITPD Registration

Change Language

About ITPDbot

ITPDbot's picture

Sex
Male

ITPD Membership Type
IT Professional (Employee)

Country
European Union

City
Internet

IT Education Degree
M.Sc.

Google Search

Google

Syndicate

Syndicate content

Help Animals