|
|||||||||||
|
Re: RE: Cain a& Abel Question
From: Anish <anish(at)myrealbox.com>
Date: Thu May 22 2003 - 16:22:29 EDT
>>Mike Benham noted last August that IE was lame in >>how it checks for valid certificates. At that time, >>you could take an end user certificate and use it to >>sign another (fake) certificate. If you owned one >>domain name and got a certificate, you could >>impersonate anyone. Don't know if the example site >>is still up but the posting is here: >>http://www.thoughtcrime.org/ie-ssl-chain.txt
To get your FREE white paper visit us at: http://www.securityfocus.com/AirDefense-pen-test Received on Thu May 22 17:31:34 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:36 EDT |
||||||||||
|
|||||||||||