Re: SSL Scanner



On 28 Okt, 04:49, Solbu <so...@xxxxxxxxxxxxxxxx> wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

royend sent the following transmission through subspace:

the project focuses on the vulnerability of
the web, and I am hoping to shove that even though SSL is implemented
the packages might be vulnerable to a Man-In-The-Middle-Attack (please
correct me if I am wrong), as the packages might be intercepted by an
attacker.

If someone intercepts the packages using a man-in-the-middle-attack,
the encryption will break, thus alerting the user.

You cannot intercept encrypted packages
without alerting the user that someone _IS_ intercepting them.
Because the certificate will be wrong.

- --
Solbu -http://www.solbu.net
Remove 'ugyldig.' for email
PGP key ID: 0xFA687324
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)

iD8DBQFHJAbBT1rWTfpocyQRAqGlAKCxkpbRHcfiYKUr10lkzQ9BBC1siwCg9/fW
ZpxgxPOj+WIKQd7tmRv8fSo=
=wwlT
-----END PGP SIGNATURE-----


On 28 Okt, 11:29, Jim Watt <jimw...@xxxxxxxxxx> wrote:
On Sat, 27 Oct 2007 08:22:11 -0700, royend <roy...@xxxxxxxxx> wrote:
Is there any programs you would recommend which will handle SSL/TLS?
Would for instance a program like Ethereal be able to read packages
using SSL protocols?

Explanation why it can't be done...
--
Jim Watt http://www.gibnet.com

That is what I thought (and hoped for...).
Can the packages be saved when intercepted and without changing the
package be used in a replay attack?

royend.

.



Relevant Pages

  • Re: SSL Scanner
    ... royend sent the following transmission through subspace: ... You cannot intercept encrypted packages ... using SSL protocols? ...
    (alt.computer.security)
  • packages, libfetch, and SSL
    ... While updates to the ports tree happen in a pretty secure ... packages added over pkg_add -r happen over plain FTP or HTTP ... The lowest-impact way to fix this, I think, is to use SSL for pkg_adds. ... libfetch needs patched to verify SSL certificate CNs and to use ...
    (freebsd-hackers)
  • Re: Apache2 - To apt or not to apt?
    ... > I need to set up a fairly complete web server (CGI, Perl, maybe SSL) ... > apt-get apache2 and the appropriate mods??? ... I would recommend the packages. ... Debian's apache2 setup is rather nice. ...
    (Debian-User)
  • where did www.debian.org/security/key-rollover/ go?
    ... In response to the latest security issue with ssl / ssh, i updated my packages ...
    (Debian-User)
  • Re: compiling sshd 3.1.0 on solaris 8 x86
    ... > Have I forget some packages ???!? ... This probably will not fix it...but you will need SSL, ...
    (comp.security.ssh)