Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




pen-test logo Penetration Testing mailing list archives

RE: Cain a& Abel Question
From: "Cushing, David" <David.Cushing () hitachisoftware com>
Date: Thu, 22 May 2003 12:37:30 -0400

Persumably a cunning attack vector would be to compromise a 
private network, generate a self signed certificate and use 
windows 2000 group policy to deliver your untrusted root ca 
as a trusted ca into everyones browser. Then C&A and Doug 
Songs tools would work without warning??

If you configured them to use that same cert for signing, you're correct.  

Of course, if you own the DC, you may want to push out a keyboard sniffer or a proxy address to capture the same data.  
ARP attacks are often noticable.

Another idea is to 'upsell' a regular (valid) certificate.

Mike Benham noted last August that IE was lame in how it checks for valid certificates.  At that time, you could take 
an end user certificate and use it to sign another (fake) certificate.  If you owned one domain name and got a 
certificate, you could impersonate anyone.  Don't know if the example site is still up but the posting is here: 
http://www.thoughtcrime.org/ie-ssl-chain.txt
--
David

---------------------------------------------------------------------------
*** Wireless LAN Policies for Security & Management - NEW White Paper ***
Just like wired networks, wireless LANs require network security policies
that are enforced to protect WLANs from known vulnerabilities and threats.
Learn to design, implement and enforce WLAN security policies to lockdown enterprise WLANs.

To get your FREE white paper visit us at:
http://www.securityfocus.com/AirDefense-pen-test
----------------------------------------------------------------------------


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]