Re: About SSLproxy running as client?

From: surya (surya@nsecure.net)
Date: 12/25/01


From: "surya" <surya@nsecure.net>
To: "colababy" <colababy@netease.com>, <focus-linux@securityfocus.com>
Date: Tue, 25 Dec 2001 13:02:41 +0530

hi,
     consider using the ssltunnel from www.stunnel.org. you can run it as
a server and put another client in the same machine.
(ProxyAware CGI- Scanner) -> (localhost 80 stunnel in client/server
mode)----->(target webserver). one limitation is that the cgi-scanner
has to support proxies.
 e.g..,
 stunnel.exe -c -d <yourmachine's ip>:80 -r <target machine>:443 -o
 c:\<logfile name>

 regards,
Suresh Ponnusami,
Internet Security Consultant,
nSecure Software (P) Ltd., INDIA

> I want take a penetration testing aiming for my SSL Web server by means
> of securetunnel or OpenSSL. I know sslproxy can be used by common scanner
> such as whisker. But it's a problem that OpenSSL for Win32 running as
client
> couldn't response for my console input. I searched for
> some tips on FAQ's, and found that the problem was just on Windows. But it
> was same result on Linux. Anyone can tell me what is't?
> By the way, merry x'mas for you!
>
>
>



Relevant Pages

  • [EXPL] Openssl-Too-Open: Apache / OpenSSL Remote Exploit
    ... openssl-too-open is a remote exploit for the KEY_ARG overflow in OpenSSL ... The CLIENT_HELLO message contains a list of the ciphers the client ... The server replies with a SERVER_HELLO message, ... The client sends a CLIENT_FINISHED message with a copy of the connection ...
    (Securiteam)
  • RE: Any tool for testing SSL servers (by modifying client HELLO)?
    ... > I believe you can use OpenSSL from the command line in linux to ... > if the server will accept any of them. ... > cipher suites i want to put in my client HELLO. ...
    (Security-Basics)
  • RE: MS crypto API based ssl proxy??
    ... I would try getting (or generating using openSSL) a set of client ... server requesting the client certificate. ... and open a connection to the server. ...
    (Pen-Test)
  • Re: What doesnt lend itself to OO?
    ... >> proxy and instructs the server to constuct the real object. ... rather than client code. ... If 'clock' is instantiated in the server, ... > for the server interface at the OOA level. ...
    (comp.object)
  • This is going straight to the pool room
    ... or not the client has privilege to do what they're trying to do, ... The server environment is this: ... 3GL User action Routines that Tier3 will execute on your behalf during the ... Routine Name: USER_INIT ...
    (comp.os.vms)