博客
关于我
强烈建议你试试无所不能的chatGPT,快点击我
Defeating SSL using SSLStrip (Marlinspike Blackhat)
阅读量:2435 次
发布时间:2019-05-10

本文共 1667 字,大约阅读时间需要 5 分钟。

 

Marlinspike made a great this year on how to subvert (HTTPS) protection used bu major sites around the Internet for security. The interesting thing is that he does not really break the SSL protocol itself, but instead demonstrates that as HTTP is the entry point into any SSL communication, subverting HTTP allows a hacker to take control of the HTTPS communication as well.

Marlinspike also released the SSLStrip tool to automate this attack, however i was not able to locate it yet on his . If anyone finds it someplace, please post a link in the comments section. Using the SSLStrip tool Marlinspike was able to retreive over 130 usernames and passwords over a Tor network. These credentials were from sites such as Gmail, Yahoo, Linkedin, Paypal etc.
The way the SSLStrip tool works by:

  1.  Does an MITM on the HTTP connection
  2. Replaces all the HTTPS links with HTTP ones but remembers the links which were changed 
  3. Communicates with the victim client on an HTTP connection for any secure link
  4. Communicates with the legitimate server over HTTPS for the same secure link
  5. Communication is transparently proxied between the victim client and the legitimate server
  6. Images such as the favicon are replaced by images of the familiar "secure lock" icon, to build trust
  7. As the MITM is taking places all passwords, credentials etc are stolen without the Client knowing

 Marlinspike also discusses other techniques such as homograph attacks to make a URL look like a legitimate one. The overall talk is very interesting. You can download the . The video posted below is of the actual Blackhat talk given by Marlinspike.

You can download a High Resolution video of the presentation

转载地址:http://qimmb.baihongyu.com/

你可能感兴趣的文章
EDS用Borland作为它的全球标准
查看>>
集成 IBM Rational RequisitePro 与 IBM Rational Portfolio Manager
查看>>
OOAD利器Rational Rose的介绍
查看>>
SCA客户端以及基于Java的模型实现(一)
查看>>
后CMMI时代的软件过程改进
查看>>
SCA及未来软件系统的开发
查看>>
CaliberRM 需求管理系统
查看>>
需求管理工具试用 – CaliberRM
查看>>
一年的测试生活和感悟
查看>>
黑盒测试
查看>>
没有需求就没有软件——需求工程简论
查看>>
使用PHP开发SCA和SDO
查看>>
通过RUP用例进行需求管理的可追踪性策略(2)
查看>>
持续改进之配置管理变更的关键路径
查看>>
SCA客户端以及基于Java的模型实现(四)
查看>>
ora2pg 字符集 转换问题总结
查看>>
postgresql 优化与维护
查看>>
mongodb replica sets 测试
查看>>
linux AS6.2 与 as5.4 的对比,性能提升明显
查看>>
FLASHCACHE 的是是非非
查看>>