Re: [Full-Disclosure] Looking for some input

Valdis.Kletnieks_at_vt.edu
Date: 05/27/04

  • Next message: Glenn_Everhart_at_bankone.com: "RE: [Full-Disclosure] Imaging Operating Systems"
    To: Shannon Johnston <sjohnston@libertysite.com>
    Date: Thu, 27 May 2004 14:17:48 -0400
    
    
    

    On Thu, 27 May 2004 10:40:17 MDT, Shannon Johnston <sjohnston@libertysite.com> said:

    > The institution where I do my banking has a login to an internet banking
    > page. While the login goes to an SSL enabled site, the login page is on
    > a non-SSL site. My question is: Doesn't this leave the members of the
    > institution open to phishing via DNS cache poisoning? Doesn't this
    > defeat the endpoint verification piece of an SSL certificate?

    Contemplate the real-world usefulness of an SSL cert.

    No, seriously - consider Matt Blaze's comment that "A CA can protect you
    against anybody they're not accepting money from" - then go read the chapter in
    Schneier's "Secrets and Lies" about it.

    Or as a faster check - how many people actually click on that little padlock,
    read the "This site has correctly identified itself" blurb, and then go the
    extra step of actually looking at the certificate to ensure it's not a spoofed
    site that's correctly identified itself under the spoofed site name? (Hint -
    would you notice if it said "The website www.g00gle.com has correctly
    identified itself"?) Oh - and do that for *every* encrypted page? ;)

    If I can hijack your connection to your bank by poisoning your ISP's DNS cache,
    I can do the exact same thing to hijack you to a typosquatter site that
    correctly identifies itself as the typosquatter site....

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: Glenn_Everhart_at_bankone.com: "RE: [Full-Disclosure] Imaging Operating Systems"

    Relevant Pages

    • Re: SSL php code
      ... > Sean I am planning on exclusievely using secure pages (ssl) after the user requests to login. ... This will securely redirect to a login ...
      (comp.lang.php)
    • Re: sendmail with smtp relay authentication
      ... LOGIN PLAIN')dnl ... the mail log and also attached the auto mail response I got. ... m31N0w2T002913: return to sender: User unknown ... 505 5.0.0 Message is sent with SSL but SSL is not allowed ...
      (comp.mail.sendmail)
    • RE: Authorize.Net Plain Text Login Transmission
      ... service provider to find out personally whether or not they are vulnerable. ... Authorize.Net Plain Text Login Transmission ... > function as if you had gone to the correct SSL version of the page. ...
      (Bugtraq)
    • Re: iis 6 ssl redirect initial login encrypted?
      ... Whilst the password isn't passed using either NTLM or Kerberos, it's not necessary for an attacker to know the password. ... another login box that uses https:// ... I just need to> get ssl ...
      (microsoft.public.inetserver.iis.security)
    • Re: Google Secure Access
      ... >> email INCLUDING CLICKING ON THAT LITTLE SSL OPTION. ... Google then SENDS YOUR LOGIN DETAILS IN THE CLEAR TO YOUR ISP. ...
      (sci.crypt)