Collected research
The Most Dangerous Code in the World
Black-box fuzzing with self-signed and mismatched-name certificates, plus source and decompiler review, showed SSL certificate validation is broken across non-browser software: Amazon and PayPal merchant SDKs, EC2 and Rackspace cloud clients, Chase mobile banking, Apache Axis and XFire middleware, and shopping carts.
Record
- Researcher
- Martin Georgiev, Subodh Iyengar, Suman Jana, Rishita Anubhai, Dan Boneh and Vitaly Shmatikov
- Published by
- cs.utexas.edu
- Format
- Whitepaper
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Martin Georgiev, Subodh Iyengar, Suman Jana, Rishita Anubhai, Dan Boneh and Vitaly Shmatikov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .