Stealing certificates

From: Rygg Christian (christian.rygg@edb.com)
Date: 11/20/02

  • Next message: SB CH: "any VPN program at linux?"
    From: Rygg Christian <christian.rygg@edb.com>
    To: "'SECURITY-BASICS@SECURITYFOCUS.COM'" <SECURITY-BASICS@SECURITYFOCUS.COM>
    Date: Wed, 20 Nov 2002 11:05:22 +0100
    
    

    Hi,

    I'm currently working on a security evaluation on a solution using https
    based on server and client certificates (stored in the browser). I have
    found the information I need on most areas, but I'm having a bit of trouble
    finding info on how easy/hard it would be for a hacker to steal a client
    certificate. Does anyone know of a good resource for this kind of
    information? Questions are along the lines of:

    What weaknesses exist in the various browsers when it comes to certificates?
    How easy would it be for a trojan to extract a certificate (with private
    key) from the various browsers?

    PS: I have found quite a lot of information on other exploits like the bug
    in IE that validates fake certificate as OK. Right now I'm just interested
    in the possibility of stealing a certificate with private key from various
    browsers.

    Thanks in advance!

    Christian Rygg



    Relevant Pages

    • SOLVED: Re: Named seems to have broken SSL
      ... Rick Anderson wrote: ... >> is not really presenting my browsers with ... >> a certificate from localhost.localdomain. ... > certificate presented, and the communication fails, since local host ...
      (Fedora)
    • RE: Stealing certificates
      ... Netscape has a problem with their method of requesting a certificate wherein ... the private key can be stolen during the certificate request process. ... > What weaknesses exist in the various browsers when it comes to ...
      (Security-Basics)
    • Re: SSL certificates -- how are they validated?
      ... it depends entirely on the client application. ... Most browsers will ... >> will check the CRLs (certificate revocation lists) along the issuer chain ...
      (microsoft.public.dotnet.security)
    • Re: [Full-disclosure] FD / lists.grok.org - bad SSL cert
      ... "software update". ... them would check the certificate the first time? ... perhaps what browsers need to start doing is to ... central CRL or through a trust rating system which is separate from the ...
      (Full-Disclosure)
    • Re: Zero terminated strings
      ... requests a certificate from the CA, the CA, using ... But an attacker can also request ... implemented in many browsers, ... If the protocol allows embedded null characters in the domain name ...
      (comp.lang.c)

  • Quantcast