SSL trick certificate published
On the Noisebridge hacker mailing list, security specialist Jacob Appelbaum has published an SSL certificate and pertinent private key that together allow web servers to avoid triggering an alert in vulnerable browsers - irrespective of the domain for which the certificate is submitted. Phishers, for example, could use the certificate to disguise their servers as legitimate banking servers – which would only be detectable by subjecting the certificate to closer scrutiny.
For his trick, Appelbaum modified the certificate according to the method demonstrated by Moxie Marlinspike at the Black Hat conference, entering a zero character (\0) in the name field (CN, Common Name).
Unlike Marlinspike, however, Appelbaum didn't enter the zero between the domain name and the name of Marlinspike's thoughtcrime.org domain. Instead, he entered *\00thoughtcrime.noisebridge.net, effectively creating a wild card certificate for arbitrary domain names:
OU = Moxie Marlinspike Fan Club
O = Noisebridge
L = San Francisco
ST = California
C = US
In a first test by the heise Security team, The H's associates in Germany, attempting to access the domain in a vulnerable browser (after adding the intermediate certificate of issuer IPS CA in the web server) did not cause an alert. Thankfully, appropriate updates to stop browsers from falling for the zero trick have been available for nearly all the popular browsers for several weeks now. Many other products and frameworks that verify server certificates when providing secure SSL connections have also been updated. Appelbaum therefore doesn't see any problems with making his "internet certificate" publicly available. The specialist says that the certificate allows developers to test their own programs for this vulnerability.
However, users should not automatically assume that their applications no longer contain the hole. Mobile phone vendor RIM, for instance, only released the certificate update for its BlackBerry products yesterday.
- Merry Certmas! CN=*\x00thoughtcrime.noisebridge.net, mailing list post from Jacob Appelbaum.
- Thunderbird 188.8.131.52 fixes SSL vulnerability, a report from The H.
- Firefox 3.5.2 and 3.0.13 fix security vulnerabilities, a report from The H.
- SSL flaw revealed at Black Hat, a report from The H.