Web Hack List

Collected research

The Most Dangerous Code in the World

Black-box fuzzing with self-signed and mismatched-name certificates, plus source and decompiler review, showed SSL certificate validation is broken across non-browser software: Amazon and PayPal merchant SDKs, EC2 and Rackspace cloud clients, Chase mobile banking, Apache Axis and XFire middleware, and shopping carts.

Record

Researcher
Martin Georgiev, Subodh Iyengar, Suman Jana, Rishita Anubhai, Dan Boneh and Vitaly Shmatikov
Published by
cs.utexas.edu
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Martin Georgiev, Subodh Iyengar, Suman Jana, Rishita Anubhai, Dan Boneh and Vitaly Shmatikov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .