Re: Stunnel Problems

From: Joerg Over (over@dexia.de)
Date: 12/07/01


Date: Fri, 07 Dec 2001 11:56:00 +0100
To: pen-test@securityfocus.com
From: Joerg Over <over@dexia.de>

Hi!

At 00:13 07.12.01 -0000 you wrote:
---8<----------------snip
->I am attempting to access a Web Server sat behind Netscape (NetCache?) 3.5
->proxy. Here is what I am doing.
->
->stunnel -c -d 80 -r <remotehost>:443
->and point a browser on local host to 80.
---8<----------------snip

I might be entirely wrong, but maybe depending on _how_ you point your
browser, it might not try to encrypt in the first place.

I'd think, that pointing like:
http://localhost/

might not even try encryption, while

https://localhost:80/

might trick the browser into it.

Just a shot in the blue, and sorry if I didn't understand the site specific
part (that looked like it might have been an entirely different access
method, using a browser directly resp. using s_client without stunnel; if
not, I'm wrong, of course)

jo

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Re: faster scans? (nmap)
    ... one host using nmap for syn scans in burst mode with the ... >>>This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: pen test help please asap
    ... > Machine A on client site makes a configurable encrypted OUTBOUND ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • Re: ettercap help
    ... Anyways have never tried Ettercap for VNC. ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: CFM SQL injection
    ... You should better use union or alike get unauthorized data from the ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: ettercap help
    ... > I can get it to sniff telnet, ftp, pop, smb, but no vnc. ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)