Archive for the 'ssl' Category

Understanding the TLS Renegotiation Attack – Educated Guesswork

Tuesday, November 10th, 2009

explains Marsh Ray’s attack in details, pls patch to fix the TLS protocol

Automated HTTPS Cookie Hijacking | fscked.org

Wednesday, September 17th, 2008

a note from security ppl that session/login cookies that normally delivered via https have to be explisidly marked as “secure” so they _only_ delivered via https. Otherwise bad ppl can hijack them.

research!rsc: Lessons from the Debian/OpenSSL Fiasco

Friday, May 23rd, 2008

good explanation of debian openssl bug. worth reading if programming is what u do for a living