Re: RE: Cain a& Abel Question

From: Anish (anish_at_myrealbox.com)
Date: 05/22/03

  • Next message: haikel: "pix log analyser"
    To: David.Cushing@hitachisoftware.com
    Date: Thu, 22 May 2003 21:22:29 +0100
    
    

    Hi David,

    >>Mike Benham noted last August that IE was lame in >>how it checks for valid certificates. At that time, >>you could take an end user certificate and use it to >>sign another (fake) certificate. If you owned one >>domain name and got a certificate, you could >>impersonate anyone. Don't know if the example site >>is still up but the posting is here: >>http://www.thoughtcrime.org/ie-ssl-chain.txt
     to best of my knowledge this bit on IE was followed by a patch ,what had happened with this was the cert chain was searched for a trusted cert and if found the cert was trusted ,without making sure the fullcert path there was trusted :-)till the CA.
     regards
    anish

    ---------------------------------------------------------------------------
    *** Wireless LAN Policies for Security & Management - NEW White Paper ***
    Just like wired networks, wireless LANs require network security policies
    that are enforced to protect WLANs from known vulnerabilities and threats.
    Learn to design, implement and enforce WLAN security policies to lockdown enterprise WLANs.

    To get your FREE white paper visit us at:
    http://www.securityfocus.com/AirDefense-pen-test
    ----------------------------------------------------------------------------


  • Next message: haikel: "pix log analyser"

    Relevant Pages

    • RE: [ANNOUNCE] protocol watcher
      ... wireless LANs require network security policies ... that are enforced to protect WLANs from known vulnerabilities and threats. ... implement and enforce WLAN security policies to lockdown enterprise WLANs. ...
      (Incidents)
    • RE: Possible Intrusion Attempt?
      ... wireless LANs require network security policies ... implement and enforce WLAN security policies to lockdown enterprise WLANs. ...
      (Incidents)
    • Re: DDoS Attack
      ... wireless LANs require network security policies ... >> that are enforced to protect WLANs from known vulnerabilities and threats. ... implement and enforce WLAN security policies to lockdown enterprise WLANs. ...
      (Incidents)
    • RE: Cain a& Abel Question
      ... wireless LANs require network security policies ... implement and enforce WLAN security policies to lockdown enterprise WLANs. ...
      (Pen-Test)
    • Re: Scans from proxyprotector.com
      ... wireless LANs require network security policies ... implement and enforce WLAN security policies to lockdown enterprise WLANs. ...
      (Incidents)