Users can install SSL Certtificates
From: Steve Mansfield (steve.mansfield_at_PENSAR.CO.UK)
Date: 01/16/04
- Previous message: Knight, Jim: "MS04-001"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Fri, 16 Jan 2004 16:48:41 -0000 To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
Hi
I am reliably informed by MS reps that there are no safeguards (ie its
not preventable by any kind of security / GPO setting etc) on users
installing SSL Certificates. I have the feeling that this isn't so
clever.
Could this be used with the URL obfuscation issue to create a chain of
'corrupt trust' baring in mind that a certificate is an entry into a
trust system?
Regards
Steve
-----
Editor's Note: The 43rd Most Powerful Person in Networking says...
Out of Office replies to list messages cause you to be unsubscribed automatically. Either subscribe a Public Folder, or ensure your rules are set to ensure list messages are filtered prior to your Out of Office reply. Such automatic replies are a bane to posters, and cause us to have fewer researchers post to NTBugtraq.
-----
- Previous message: Knight, Jim: "MS04-001"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]