[prev in list] [next in list] [prev in thread] [next in thread]
List: bugtraq
Subject: Re: AW: IE https certificate attack
From: George Staikos <staikos () 0wned ! org>
Date: 2002-01-06 17:11:14
[Download RAW message or body]
On Thursday 03 January 2002 09:04, K.J.Mueller@EnBW.com wrote:
> could it be, that the text-browsers (lynx, links, w3m) don't even
> bother comparing the actual server name to the certificate's
> "issued for" entry?
> > Looks like Konqueror 2.2.1 (Mandrake Linux 8.1 + OpenSSL 0.9.6b) is also
> > vulnerable. I've got no warning when entering on this page. I've tested
> > it
The https implementation in Konqueror is incomplete. As of 2.2.2 it is
much more complete, although the code to test CN=hostname doesn't work
properly. This is fixed in KDE 2.2 branch CVS and KDE 3.x HEAD branch. KDE
3.0 should feature a more-or-less full HTTPS implementation finally.
Most of the incomplete code and bugs in KDE SSL are documented anyways.
--
George Staikos
[prev in list] [next in list] [prev in thread] [next in thread]
Configure |
About |
News |
Add a list |
Sponsored by KoreLogic