Yet more Web security flaws have emerged to threaten Internet users, who are already bedeviled by the likes of drive-by attacks, SQL injections and spam. At the Black Hat security conference in Las Vegas, researchers reportedly demonstrated serious flaws in the Secure Sockets Layer encryption protocol, a commonly used method of protecting communications on the Web. One attack, demonstrated by security researcher Moxie Marlinspike, intercepts SSL traffic using a null-termination certificate — a certificate containing null characters such as “.”
Security Testers Spot Worrisome Weakness in SSL
Posted by: Richard Adhikari July 30, 2009 12:21 PMYet more Web security flaws have emerged to threaten Internet users, who are already bedeviled by the likes of drive-by attacks, SQL injections and spam. At the Black Hat security conference in Las Vegas, researchers reportedly demonstrated serious flaws in the Secure Sockets Layer encryption protocol, a commonly used method of protecting communications on the Web. One attack, demonstrated by security researcher Moxie Marlinspike, intercepts SSL traffic using a null-termination certificate — a certificate containing null characters such as “.”