Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 06:35:34 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=1927076668&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2F0911-advisories%2FRenegotiating_TLS.pdf%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.1927076668.1338186934.1338186934.1338186934.1%3B%2B__utmz%3D32867617.1338186934.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) Renegotiating TLS Man-In-The-Middle http://packetstormsecurity.org/files/82497/Renegotiating_TLS.pdf http://packetstormsecurity.org/files/82497/Renegotiating_TLS.pdf http://packetstormsecurity.org/files/82497/Renegotiating-TLS-Man-In-The-Middle.html Thu, 05 Nov 2009 19:40:42 GMT Paper called Renegotiating TLS. Transport Layer Security (TLS, RFC 5246 and previous, including SSL v3 and previous) is subject to a number of serious man-in-the-middle (MITM) attacks related to renegotiation. In general, these problems allow an MITM to inject an arbitrary amount of chosen plaintext into the beginning of the application protocol stream, leading to a variety of abuse possibilities. In particular, practical attacks against HTTPS client certificate authentication have been demonstrated against recent versions of both Microsoft IIS and Apache httpd on a variety of platforms and in conjunction with a variety of client applications. Cases not involving client certificates have been demonstrated as well.