Web Hack List

Collected research

Using Frankencerts for Automated Adversarial Testing of Certificate Validation in SSL/TLS Implementations

Generates frankencerts by randomly mutating parts of millions of real X.509 certificates, then differentially tests eight SSL/TLS libraries against each other so that any disagreement flags a validation bug. Found 208 discrepancies, including MatrixSSL and GnuTLS accepting any valid X.509v1 certificate as a CA, which enables man-in-the-middle attacks.

Record

Researcher
Chad Brubaker, Suman Jana, Baishakhi Ray, Sarfraz Khurshid and Vitaly Shmatikov
Published by
ieee-security.org
Format
Whitepaper
Topic
Crypto

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Chad Brubaker, Suman Jana, Baishakhi Ray, Sarfraz Khurshid and Vitaly Shmatikov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .