Re: IE https certificate attack

From: Dimitris Giannitsaros (daremon@ath.forthnet.gr)
Date: 12/24/01


From: "Dimitris Giannitsaros" <daremon@ath.forthnet.gr>
To: <security@e-matters.de>, <bugtraq@securityfocus.com>
Date: Mon, 24 Dec 2001 22:20:12 +0200

I use IE 5.00.3315.1000 / Win2k Pro SP2 and no other patches. I am not
vulnerable: IE correctly displays the warning ("Security Alert") saying that
"The name on the security certificate does not match the name of the site"
and asking whether i want to continue. From this message i can also choose
"View Certificate" where i see that it is published for ssl-ematters.de and
not suspekt.org...

Dimitris

> Proof of Concept:
>
> A proof of concept webpage was put up at http://suspekt.org. Clicking
> onto the "To the secure page..." link will send your browser to
> https://suspekt.org without IE warning you that the certificate was not
> issued onto that server.
>
> This is not a MIM but it has the same effect: IE will tell you a page
is
> secure although the certificate is illegal and its possible for a third
> party (anyone who owns the given certificate) to decrypt your traffic
in
> realtime.



Relevant Pages

  • RE: Certificates Security Alert Errors
    ... I would rerun the connect to the internet wizard ... | Subject: Certificates Security Alert Errors ... | is trusted, the date is valid, but the name on the security certificate is ... For SBS 4.5 issues, post to: ...
    (microsoft.public.windows.server.sbs)
  • Re: OWA + Loading ...
    ... To get rid of that security alert, you need to add the certificate to you ... > within the corp. network which is great news. ... > complete with emails and no loading... ...
    (microsoft.public.exchange2000.general)
  • Re: (New Subject): How to eliminate prompt for credentials when using RPC over HTTP
    ... >> that it is installed on the client running Outlook 2003. ... a web server certificate is automatically created when you ... >> run the Configure E-mail and Internet Connection Wizard. ... >> cause a security alert, you can install the certificate on the client. ...
    (microsoft.public.windows.server.sbs)
  • (New Subject): How to eliminate prompt for credentials when using RPC over HTTP
    ... that your Outlook 2003 client must be running on XP Pro for this to work. ... *Certificate Configuration* ... To avoid the security alert pop-up, ...
    (microsoft.public.windows.server.sbs)
  • Security Alert: Certificate Warning
    ... >The security alert is the one with the Yes, ... >Certificate button. ... Although my test in normal mode with all the ... >Can anyone tell me exactly what safemode does not load so ...
    (microsoft.public.windows.inetexplorer.ie6.browser)