Software sorta lets you cut through SSL encryption like nobody’s business
Nick | Feb 24, 2009 | Comments 0
Break out the siren.gif! One of those security research types demonstrated last week how he was able to get around SSL authentication, enabling him to collect private information—Gmail login/passwords, credit card numbers, and the like—with very little trouble at all. It’s not a flaw in SSL itself, but a flaw in the way people use the Web.
The researcher, Moxie Marlinspike (that’s what he goes by, at least), developed an application called SSLstrip that uses a simple man in the middle (MITM) attack to force the victims’ browsers to forward all information—passwords and the like—to his computer before going to, say, Gmail. Say you type gmail.com into your browser, instead of going straight to Google’s servers, the request is routed through the computer where SSLstrip is installed, which then passes on the request to Google’s servers; you, the user who initially typed gmail.com into your browser, has no idea that your info was redirected somewhere else, of course.
As for the SSL stripping itself
The quick solution to defend against this is to go directly to SSL sites by typing https://whatever.com into your address bar.
I seem to recall Ettercap having a similar feature, being able to read SSL-encrypted traffic.
crunchgear.com
|Filed Under: Technology News
Relax, Britons, you won’t be kicked off the Internet for downloading music
Borderlands' Creative Boss Lives Up to His Loot Promises
New Google Affiliate Network Features: Rising Stars, Recruiting Tools and Links UI
Rumor: Nokia still looking at netbooks, going with Foxconn as the OEM?
Obama, CIA chief patch up interrogation-memo rift
Jury to deliberate in MySpace suicide case
Qik To Come Pre-Loaded On New Nokia Phone
NVIDIA launches the Quadro CX GPU for graphic professionals
Nokia 5800 XpressMusic promo shots spotted
Sony VAIO P heading to Verizon for $300 with contract?
Review: BlackBerry Storm for Verizon Wireless
3 Awesome Sites for Stumbling Across the Best of the Web