Re: Can SSL sessions be compromised?



comphelp@xxxxxxxxx (Todd H.) writes:
Specify a version level of SSL (greater than known-weak SSL v 2.0)
that this applies to, or a specific implementation's flaw, cite

re:
http://www.garlic.com/~lynn/2007g.html#32 Can SSL sessions be compromised?
http://www.garlic.com/~lynn/2007g.html#38 Can SSL sessions be compromised?

SSL is suppose to do two things ... 1) are you really talking to the
webserver that you think you are talking to and 2) hide/encrypt
information during transmission.

the attacks that I'm aware have been with regard to the first item
.... including allowing various kinds of MITM-attacks (as mentioned
in previous posts).

recent post about MITM-attack
http://www.garlic.com/~lynn/aadsm26.htm#47 SSL MITM-attacks make the news

as well blog discussion

THREATWATCH: MITB SPOTTED: MITM OVER SSL FROM WITHIN THE BROWSER
https://financialcryptography.com/mt/archives/000884.html

.



Relevant Pages

  • Re: Can SSL sessions be compromised?
    ... http://www.garlic.com/~lynn/2007g.html#32 Can SSL sessions be compromised? ... including allowing various kinds of MITM-attacks (as mentioned ... which if it actually exists must be a compromise that is ...
    (comp.security.misc)
  • Re: SSL vs HTTPS
    ... Eduardo wrote: ... > Could anyone explain to me the difference between SSL and HTTPS? ... SSL over HTTP, the actual implementation of the SSL protocol for HTTP. ... It includes things like the port number used for SSL sessions (by ...
    (comp.security.ssh)
  • Why is .NET CF 2.0 (HttpWebRequest Class) using 40-bit Encryption over HTTPS?
    ... This post is a continuation of these previous posts: ... I am investigating how to properly implement SSL Certificates because our ... I'm trying to determine why the encryption ... installed our SSL Cert on the mobile device (see previous posts listed ...
    (microsoft.public.dotnet.framework.compactframework)
  • Re: WinVN FACE support added [was] WinVN Command Line?
    ... the top of my personal request list is SSL support. ... But for your SSL test needs, ... They have a 25 posts per day posting limitation, ...
    (news.software.readers)
  • Re: SSL
    ... You need to find a way to do that, when you go from SSL to normal page, the ... parameter to indicate that this person has login in the response.redirect ... the https:// page posts to an http:// page. ... >>> Any sample code would be greatly appreciated. ...
    (microsoft.public.inetserver.iis.security)