Description: <div style="text-align: justify;"> This talk titled "<span style="font-weight: bold;">More Tricks For Defeating SSL</span>" was given by Moxie MarlinSpike at Defcon 17 this year.<br><br><span style="font-weight: bold;">Abstract:</span> This talk aims to pick up where SSL stripping left off. While sslstrip ultimately remains quite deadly in practice, this talk will demonstrate some new tricks for defeating SSL/TLS in places where sslstrip does not reach. Cautious users, for example, have been advised to explicitly visit https URLs or to use bookmarks in order to protect themselves from sslstrip, while other SSL/TLS based protocols such as imaps, pop3s, smtps, ssl/irc, and SSL-based VPNs never present an opportunity for stripping. This talk will outline some new tools and tricks aimed at these points of communication, ultimately providing highly effective attacks on SSL/TLS connections themselves.<br><br style="font-weight: bold;"><span style="font-weight: bold;">You can download the original high resolution video </span>from here<span style="font-weight: bold;">.</span><br><br><br></div><style type="text/css"> body { background: #FFF; } </style>
Tags: basics ,
Disclaimer: We are a infosec video aggregator and this video is linked from an external website. The original author may be different from the user re-posting/linking it here. Please do not assume the authors to be same without verifying.