Skip to main content

Moxie Marlinspike releases SSLstrip

posted onFebruary 18, 2009
by hitbsecnews

On Wednesday, at the Black Hat security conference here, an independent hacker and security researcher who goes by the name Moxie Marlinspike announced that he would release a software tool for performing "man-in-the-middle" attacks on seemingly secure Web sites, including banking sites, Web e-mail or e-commerce sites.

This free program, which Marlinspike calls "SSLstrip," will allow hackers to remove the encryption or Secure Sockets Layer (SSL) protection intended to make sites safe. A cybercriminal would then have access to any passwords or other sensitive information traveling unprotected over the network.

Marlinspike's SSLstrip sits on a local network and intercepts traffic. When it detects an encrypted HTTPS (Hypertext Transfer Protocol Secure) site, it automatically substitutes a look-alike of the intended destination as an unencrypted HTTP site. That switching trick strips away the security that prevents a third party from stealing or modifying data, while telling the server that an encrypted page has been sent.

Source

Tags

Software-Programming

You May Also Like

Recent News

Thursday, May 16th

Wednesday, May 15th

Tuesday, May 14th

Monday, May 13th

Friday, May 10th

Thursday, May 9th

Wednesday, May 8th

Tuesday, May 7th