Evading Client-Certificate Authentication

From: Kevin Vanhaelen (blowfish448_at_hotmail.com)
Date: 03/31/04

  • Next message: Jason: "Re: Evading Client-Certificate Authentication"
    To: <pen-test@securityfocus.com>, <webappsec@securityfocus.com>
    Date: Wed, 31 Mar 2004 22:43:56 +0200
    
    

    Hi to all,

    whilst in the middle of a Penetration Test I stumbled on a web server only
    serving SSL and demanding the client to present
    a certificate to identify himself.
    I tried to nikto it with sslproxy and browse the site thru paros both with a
    temporary Verisign personal certificate.
    No such luck, the server keeps bouncing me off. Even vulnerability scanners
    like Nessus and Retina don't get passed
    the port-scan portion.

    Does anyone have an idea to further assess this server? Am I looking at a
    mission impossible here maybe?

    Thanks,

    ~kevin

    ---------------------------------------------------------------------------
    You're a pen tester, but is google.com still your R&D team?
    Now you can get trustworthy commercial-grade exploits and the latest
    techniques from a world-class research group.
    www.coresecurity.com/promos/sf_ept1
    ----------------------------------------------------------------------------


  • Next message: Jason: "Re: Evading Client-Certificate Authentication"

    Relevant Pages

    • Re: Need for encryption in WSE 3.0 if using SS-avoid man-in-middle
      ... SSL only validates you are talking to a SSL certified server; ... They can simply edit the URL the client program ... can be done by using a X.509 certificate on both ends, ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: LDP client authentication fails
      ... I got the LDP working with LDAP server under server client authentication ... I did not installed the certificate in pfx format .. ... Client cert auth won't work without that. ...
      (microsoft.public.windows.server.active_directory)
    • Re: SSL & Man In the Middle Attack
      ... >> it possible for the middle man to intercept all messages from server to me ... > server sends client a signed message along with a digital certificate. ... > client generates a random secret key, ...
      (comp.security.misc)
    • Re: activesync issue
      ... On the SBS 2003 Server open the Server Management console. ... On the "Web Server Certificate" page, choose to create a new Web server ... Install the new certificate which created in above step on mobile device: ... Access to browse the Exchange Server 2003 client after you install ...
      (microsoft.public.windows.server.sbs)
    • Re: Need for encryption in WSE 3.0 if using SS-avoid man-in-middle
      ... order to detect we are connected to the wrong server (even though its SSL ... certificate is OK and valid by Verisign); we would need a client certificate. ... this can be detected by SSL/HTTPS client in ...
      (microsoft.public.dotnet.framework.aspnet.security)