[26905] in bugtraq

home help back first fref pref prev next nref lref last post

Re: **maillist:: Outlook S/MIME Vulnerability

daemon@ATHENA.MIT.EDU (Thomas Seliger)
Tue Sep 3 17:04:44 2002

Message-ID: <3D74C1EF.6030707@spammotel.com>
Date: Tue, 03 Sep 2002 16:06:39 +0200
From: Thomas Seliger <SQEHXLLBQUJX@spammotel.com>
MIME-Version: 1.0
To: bugtraq@securityfocus.com
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit

Since the failure of checking certificate chain correctly seems to be 
buried deeper in windows (maybe in some DLL? some info from microsoft 
would be greatly appreciated, but their security offensive seems to be 
hot air anyway), i could imagine more possibilities to exploit it:

* certificates of components:
anyone tried to spoof the certificates of components (like plugins) that 
are installed if you click on them?

* certificates used for IPSec authentication:
windows 2000 includes a IPSec implementation, authentication can be done 
by certificates. If i remember correctly, you can define a CA that is 
signing your IPSec partners, so that you can trust the IPSec connection 
partner. Can you spoof that also?

cu
Thomas Seliger







home help back first fref pref prev next nref lref last post