Re: IE https certificate attack

From: Diego M. Vadell (dvadell@uyr.com.ar)
Date: 12/25/01


Date: Tue, 25 Dec 2001 16:12:25 -0300
From: "Diego M. Vadell" <dvadell@uyr.com.ar>
To: bugtraq@securityfocus.com

Hi,
        Just FYI, I did get a warning as soon as I entered http://suspekt.org/ with Konqueror from KDE3beta1.

"The Ip address of the host supekt.org does not match the one the certificate was issued to."

        Diego.

On Tue, 25 Dec 2001 16:14:39 +0100
"Przemyslaw Frasunek" <venglin@freebsd.lublin.pl> wrote:

> On Saturday 22 December 2001 15:37, security@e-matters.de wrote:
> > A proof of concept webpage was put up at http://suspekt.org. Clicking
> > onto the "To the secure page..." link will send your browser to
> > https://suspekt.org without IE warning you that the certificate was not
> > issued onto that server.
>
> Looks like Konqueror 2.2.1 (Mandrake Linux 8.1 + OpenSSL 0.9.6b) is also
> vulnerable. I've got no warning when entering on this page. I've tested it
> also with lynx 2.8.4rel.1 (compiled with OpenSSL 0.9.6a on FreeBSD) with the
> same result.
>
> --
> * Fido: 2:480/124 ** WWW: http://www.frasunek.com/ ** NIC-HDL: PMF9-RIPE *
> * Inet: przemyslaw@frasunek.com ** PGP: D48684904685DF43EA93AFA13BE170BF *



Relevant Pages

  • Re: Sendmail TLS with multiple virtual domains
    ... be responsible for a single certificate to represent it's hostname. ... It's impossible for any MTA to have multiple certificates without using ... multiple IP addresses - the server has no way of knowing which host name ...
    (comp.mail.sendmail)
  • Where to View Machine Certificate?
    ... When you login to a host using the latest version of RDP, ... it uses the host certificate to match the name of the target ... A new Windows Server 2003 install had its machine name changed and now the ...
    (microsoft.public.windows.server.security)
  • Re: IIS5/IIS6 - Creating CSR - where to enter SAN/UC?
    ... server names with one certificate. ... Microsoft Exchange Server 2007 and Office Communications Server, ... Subject Alternative Names let you protect multiple host names with a single ... protected by a single SSL certificate. ...
    (microsoft.public.inetserver.iis.security)
  • Re: https is it realy that safe?
    ... > You have one host and one server running apache https and between them ... > a hacker listening to everything. ... > certificate that the server is sending. ...
    (comp.security.unix)
  • Re: Wildcard SSL Certificates
    ... > certificate for my domain. ... and can represent itself as some/any host in the specified domain ... use of front-end redirection in server boundary router (interfacing ... of having correctly issued you a wildcard certificate ... ...
    (comp.security.misc)