Re: IE https certificate attack

From: Donald King (donald_king@mail.com)
Date: 12/26/01


From: Donald King <donald_king@mail.com>
To: bugtraq@securityfocus.com
Date: Wed, 26 Dec 2001 12:32:15 -0600

On Sat 22 Dec 2001 08:37, security@e-matters.de wrote:
  [Snip]
> A flaw in Microsoft Internet Explorer allows an attacker to perform
> a SSL Man-In-The-Middle attack without the majority of users
> recognising it. In fact the only way to detect the attack is to manually
> compare the server name with the name stored in the certificate.
>
  [Snip]

I have confirmed the following on my own system:
 * Konqueror 2.1 is VULNERABLE;
 * Mozilla 0.9.6 is not vulnerable;
 * Netscape 4.75 is not vulnerable.

-- 
Donald King, a.k.a. Chronos Tachyon
http://chronos.dyndns.org/ -- WWED?
Guardian of Eristic Paraphernalia
Gatekeeper of the Region of Thud
 12:17pm  up 59 days, 16:03,  1 user,  load average: 0.13, 0.13, 0.09



Relevant Pages

  • Re: StrongNameIdentityPermission LinkDemand versus internal
    ... nor SNIP provide any ... serious deterrent to a determined and/or priviledged attacker. ... Low accessibility helps you constrain even your own use of your code. ... Make attempted breach of the protections an offense under any relevant ...
    (microsoft.public.dotnet.framework)
  • RE: Trojan injected in my Freebsd 4.1-RELEASE
    ... you just want to learn about the hacker. ... around 5 hours ago (per the deletion of your wtmp). ... identifying your attacker. ...
    (FreeBSD-Security)
  • Re: Wireless security
    ... > Paranoia says if a really good attacker wanted to, ... In this respect I believe you should know what kind of adversery you are ... worry about wireless security in the first place. ...
    (comp.security.misc)
  • Re: Wireless security
    ... > Paranoia says if a really good attacker wanted to, ... In this respect I believe you should know what kind of adversery you are ... worry about wireless security in the first place. ...
    (alt.computer.security)
  • Re: Windows Explorer
    ... 'Microsoft Internet Explorer'. ... Remove the /e, and click apply, and it wont say that any more. ... Remove my socks for email address ...
    (microsoft.public.windowsxp.general)