메뉴 건너뛰기




Volumn , Issue , 2012, Pages 38-49

The most dangerous code in the world: Validating SSL certificates in non-browser software

Author keywords

HTTPS; Public key certificates; Public key infrastructure; Security vulnerabilities; SSL; TLS

Indexed keywords

HTTPS; PUBLIC KEY CERTIFICATES; PUBLIC KEY INFRASTRUCTURE; SECURITY VULNERABILITIES; SSL; TLS;

EID: 84869429339     PISSN: 15437221     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1145/2382196.2382204     Document Type: Conference Paper
Times cited : (389)

References (23)
  • 1
    • 84870646671 scopus 로고    scopus 로고
    • https should check CN of x509 cert
    • https should check CN of x509 cert. https://issues.apache.org/jira/ browse/HTTPCLIENT-613.
  • 2
    • 85032541897 scopus 로고    scopus 로고
    • Remote timing attacks are practical
    • D. Brumley and D. Boneh. Remote timing attacks are practical. In USENIX Security, 2003.
    • (2003) USENIX Security
    • Brumley, D.1    Boneh, D.2
  • 3
    • 70449625210 scopus 로고    scopus 로고
    • Pretty-Bad-Proxy: An overlooked adversary in browsers' HTTPS deployments
    • S. Chen, Z. Mao, Y.-M. Wang, and M. Zhang. Pretty-Bad-Proxy: An overlooked adversary in browsers' HTTPS deployments. In S&P, 2009.
    • (2009) S&P
    • Chen, S.1    Mao, Z.2    Wang, Y.-M.3    Zhang, M.4
  • 4
    • 77955197190 scopus 로고    scopus 로고
    • Side-channel leaks in Web applications: A reality today, a challenge tomorrow
    • S. Chen, R. Wang, X. Wang, and K. Zhang. Side-channel leaks in Web applications: A reality today, a challenge tomorrow. In S&P, 2010.
    • (2010) S&P
    • Chen, S.1    Wang, R.2    Wang, X.3    Zhang, K.4
  • 5
    • 84870642197 scopus 로고    scopus 로고
    • Comodo report of incident. http://www.comodo.com/Comodo-Fraud-Incident- 2011-03-23.html, 2011.
    • (2011)
  • 7
    • 80053025624 scopus 로고    scopus 로고
    • An observatory for the SSLiverse
    • P. Eckersley and J. Burns. An observatory for the SSLiverse. In DEFCON, 2010.
    • (2010) DEFCON
    • Eckersley, P.1    Burns, J.2
  • 10
    • 84869398182 scopus 로고    scopus 로고
    • PKI layer cake: New collision attacks against the global X.509 infrastructure
    • D. Kaminsky, M. Patterson, and L. Sassaman. PKI layer cake: new collision attacks against the global X.509 infrastructure. In FC, 2010.
    • (2010) FC
    • Kaminsky, D.1    Patterson, M.2    Sassaman, L.3
  • 11
    • 84914182768 scopus 로고    scopus 로고
    • Moxie Marlinspike
    • Moxie Marlinspike. IE SSL vulnerability. http://www.thoughtcrime.org/ie- ssl-chain.txt, 2002.
    • (2002) IE SSL Vulnerability
  • 14
    • 2942597551 scopus 로고    scopus 로고
    • HTTP over TLS. http://www.ietf.org/rfc/rfc2818.txt, 2000.
    • (2000) HTTP over TLS
  • 20
    • 84870634888 scopus 로고    scopus 로고
    • CVE-2009-4831. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009- 4831, 2009.
    • (2009)
  • 23
    • 80051991045 scopus 로고    scopus 로고
    • How to shop for free online - Security analysis of cashier-as-a-service based Web stores
    • R. Wang, S. Chen, X. Wang, and S. Qadeer. How to shop for free online - Security analysis of cashier-as-a-service based Web stores. In S&P, 2011.
    • (2011) S&P
    • Wang, R.1    Chen, S.2    Wang, X.3    Qadeer, S.4


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.