Null-Prefix SSL Certificate For PayPal Released
“Nine weeks after Moxie Marlinspike presented at Defcon 17, null-prefix certificates that exploit the SSL certificate vulnerability are beginning to appear. Yesterday, someone posted a null-prefix certificate for www.paypal.com on the full-disclosure mailing list. In conjunction with sslsniff, this certificate can be used to intercept communication to PayPal from all clients using the Windows Crypto API, for which a patch is still not available. This includes IE, Chrome, and Safari on Windows. What’s worse, because of the OCSP attack that Moxie also presented at Defcon, this certificate cannot be revoked.”
via Slashdot IT Story | Null-Prefix SSL Certificate For PayPal Released.
heh… windows pwned again
You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.