Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 30 guests online
 
Advertisement

You are here: Home arrow Resourcesarrow Toolsarrow Attacking SSL - SSLStrip
EH-Net
May 20, 2013, 05:25:08 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Attacking SSL - SSLStrip  (Read 6163 times)
0 Members and 1 Guest are viewing this topic.
Jhaddix
Sr. Member
****
Offline Offline

Posts: 317



View Profile WWW
« on: February 24, 2009, 02:51:49 AM »

This is one of the buzz presentations on SSL at Blackhat, the one Chris said he missed, well... here it is. The article, the tool and the video of presentation.

VERY similiar to The Middler by Jay beale? SSL becomes less and less appealing. In conjunction both tools are valuable.

Tool: SSLStrip

Video of Presentation: New tricks for defeating SSL in Practice

PDF Slides

Searchsec article below

Quote
How do you exploit Hypertext Transfer Protocol Secure (HTTPS), tightly wrapped in SSL or TLS?

According to Moxie Marlinspike, you don't. You exploit the HTTP it's built on. If you think about it, he told a Black Hat DC Briefings audience Wednesday, people encounter SSL by clicking on a link and being redirected to an HTTPS-secured page when they log into banking, webmail or shopping websites.

Marlinspike unveiled a hacking technique which intercepts Web traffic and tricks users into giving up passwords and other sensitive information. With the aid of a new tool called SSLstrip, Marlinspike demonstrated how easy it is to trick users into thinking they are on a trusted, secure website.

"People only encounter HTTPS via HTTP, so maybe we can think about starting by attacking HTTP," he said. "Normally, if we're doing man-in-the-middle attacks against SSL, we go straight for SSL, straight after that connection. But if SSL depends on this other protocol, why don't we look at that first?"

The trick, said Marlinspike, is duplicating a Web environment in which people are comfortable, in which they feel safe. Not long ago, he said, websites emphasized what he called positive feedback. You see the ubiquitous padlock icon and perhaps the URL address window turned a reassuring color.

But now, newer browsers like Firefox 3 and IE8 display dire, in-your-face warnings that only the most reckless Web surfer would ignore. So, if you're trying to trick people into inputting their credit card numbers into Web pages they think are secured by SSL --but that you own -- you want them to see a page that looks almost, if not completely normal. Positive feedback is pretty subtle.

"If we trigger negative feedback, we're totally screwed. People only care if it's catastrophic problem: 'Look out!'" he said. "If we fail to trigger positive feedback, maybe it's not so bad. People aren't really keeping an eagle eye out for all those positive indicators."

The basic idea is to intercept Web traffic with a new tool called SSLstrip. The tool switches the hyperlink reference (href) from HTTPS to HTTP and swaps the user to an insecure look-alike page. The server thinks everything is secure, because it is unaware of the exchange between the victim and the client, and the client gets no warning.

ou can even add your own padlock icon to improve the user's comfort level.

Once you've got what you want from the victim, SSLstrip can be set to drop out and the user is once again presented with an SSL-protected page after the damage is done.

User names and passwords are particularly desirable targets.

"The real nice thing about passwords is that people reuse their passwords. So, if you get their passwords to one site, you've probably got their passwords to 10 or more sites," Marlinspike said.
« Last Edit: February 24, 2009, 03:52:15 AM by Jhaddix » Logged

Jhaddix
Sr. Member
****
Offline Offline

Posts: 317



View Profile WWW
« Reply #1 on: February 24, 2009, 05:30:27 AM »

Aside from this getting A LOT of press, here is the blackhat interview Jeff Moss did with him:

Jeff Moss w/Moxie Marlinspike
Logged

Ne0
Jr. Member
**
Offline Offline

Posts: 62


View Profile
« Reply #2 on: February 24, 2009, 03:27:40 PM »

jhaddix

good one, yeah heard abt him today morning, now banks and ecommerce, or other secure educational community would be sweating after this tools release now nothing is more secure now.... i wish .gov, .edu. .in. are searching for some other creepy secure ways to escape from this
Logged
kcirtap
Newbie
*
Offline Offline

Posts: 9


View Profile
« Reply #3 on: February 25, 2009, 02:14:13 PM »

just finished watching the video a while ago... scarry... Shocked
Logged

C|EH, GPEN
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #4 on: February 25, 2009, 03:01:07 PM »

I watched it, actually used it as a CPE for a couple of certs Smiley   It was definitely a good presentation.  I guess a couple of browsers from now, some of the issues will be fixed to limit this attacks' effectiveness.  It's just one thing after another for SSL, isn't it?   Session hijacking, sidejacking, ssl stripping, oh my.
Logged

~~~~~~~~~~~~~~
Ketchup
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 1.135 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.