Re: Need to monitor SSL going out of my network

From: nick black (dank_at_suburbanjihad.net)
Date: 08/15/03

  • Next message: Will Schmied: "RE: Tool to remotely detect MBlaster infected machines?"
    To: focus-ids@securityfocus.com
    Date: Fri, 15 Aug 2003 14:46:01 +0000 (UTC)
    
    

    windows were scaled to handle Daniel Velez's outburst:
    > What options are available to me if I need to monitor the SSL HTTPS
    > traffic from users on my network to an SSL web server outside that
    > requires client authentication during the handshake?

    eric rescorla (author of ssl & tls: designing and building secure
    systems) offers his excellent ssldump tool for free at
    www.rtfm.com/ssldump. it'll decode and summarize ssl records, and in an
    escrow situation can decode application traffic.

    -- 
    nick black <dank@reflexsecurity.com>
    "np:  nondeterministic polynomial-time
    the class of dashed hopes and idle dreams." - the complexity zoo
    ---------------------------------------------------------------------------
    Captus Networks - Integrated Intrusion Prevention and Traffic Shaping  
     - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans
     - Automatically Control P2P, IM and Spam Traffic
     - Ensure Reliable Performance of Mission Critical Applications
    Precisely Define and Implement Network Security and Performance Policies
    **FREE Vulnerability Assessment Toolkit - WhitePapers - Live Demo
    Visit us at: http://www.captusnetworks.com/ads/31.htm
    ---------------------------------------------------------------------------
    

  • Next message: Will Schmied: "RE: Tool to remotely detect MBlaster infected machines?"

    Relevant Pages

    • Re: Can I set 2 SSL Certificate for one IP?
      ... I'm not doubting the integrity of SSL and using OWA. ... "assuming" someine is already inside of your network and if that is the case ... Well, then, you go right ahead and continue using HTTP. ...
      (microsoft.public.exchange.admin)
    • Re: Funlove virus attacking Print ques
      ... I have a honeypot machine setup on each major subnet on my network that ... basically does a "net sessions" every 10 Minutes, pipes that output to a log ... Do you have 128-bit SSL encryption server security? ...
      (NT-Bugtraq)
    • Re: Having both SSL -AND- VPN...
      ... On the one hand, SSL is quite secure, as are most popular VPN ... said that a network is too secure. ...
      (comp.security.firewalls)
    • Re: Do I really need a wild card certificate ?
      ... Looks like you and Funkadyleik are correct it is a network issue, ... When I browse to the SSL enabled virtual directory from within my work ... Wildcard cert is typicall more expensive then normal SSL cert, ...
      (microsoft.public.inetserver.iis.security)
    • Re: IPSec to encrypt SMB traffic?
      ... I'd like to know what you find regarding this - we've seen our network guys ... >decrypting ssl payload. ... If the router is a ... >proxy server such as ISA and the proxy is the endpoint for the ssl then I ...
      (microsoft.public.windowsxp.security_admin)