Re: IE https certificate attack

From: Przemyslaw Frasunek (venglin@freebsd.lublin.pl)
Date: 12/25/01


From: Przemyslaw Frasunek <venglin@freebsd.lublin.pl>
To: security@e-matters.de, bugtraq@securityfocus.com
Date: Tue, 25 Dec 2001 16:14:39 +0100

On Saturday 22 December 2001 15:37, security@e-matters.de wrote:
> A proof of concept webpage was put up at http://suspekt.org. Clicking
> onto the "To the secure page..." link will send your browser to
> https://suspekt.org without IE warning you that the certificate was not
> issued onto that server.

Looks like Konqueror 2.2.1 (Mandrake Linux 8.1 + OpenSSL 0.9.6b) is also
vulnerable. I've got no warning when entering on this page. I've tested it
also with lynx 2.8.4rel.1 (compiled with OpenSSL 0.9.6a on FreeBSD) with the
same result.

-- 
* Fido: 2:480/124 ** WWW: http://www.frasunek.com/ ** NIC-HDL: PMF9-RIPE *
* Inet: przemyslaw@frasunek.com ** PGP: D48684904685DF43EA93AFA13BE170BF *



Relevant Pages

  • Re: What is the most secure web browser,
    ... > the most secure graphical browsers. ... > security of the browser can be defined within the ... > browser itself or by restricting the sites the users ... > D) Disable certain bugs by event correlation (I think ...
    (Security-Basics)
  • Re: FW: aa.com not encrypting customer transaction data (KMM508728C0KM)
    ... security we use to transfer confidential customer information. ... Most browsers indicate that a page is secure by one or more of the ... Our site will access secure servers for user confidentiality only when ... frames which contain this information and is the reason your browser is ...
    (Bugtraq)
  • What is the most secure web browser,
    ... the most secure “graphical” browsers. ... browser itself or by restricting the sites the users ... The security community has created ... >> obviously not the secure web browser of choice. ...
    (Security-Basics)
  • Re: Browser hijacker?
    ... >create a log file that can be sent to a forum that can ... >> appears to have downlaoded a 'secure content browser'. ... >> from the tools dropdown menu? ...
    (microsoft.public.windows.inetexplorer.ie6.setup)
  • Close browser window & open another
    ... Windows Integrated Security is being used. ... When a MIS Tech is at another employees pc, and they log into the secure ... Do I need to have the browser close, and open up another browser window? ...
    (microsoft.public.vsnet.general)