Collected research
Using Frankencerts for Automated Adversarial Testing of Certificate Validation in SSL/TLS Implementations
Generates frankencerts by randomly mutating parts of millions of real X.509 certificates, then differentially tests eight SSL/TLS libraries against each other so that any disagreement flags a validation bug. Found 208 discrepancies, including MatrixSSL and GnuTLS accepting any valid X.509v1 certificate as a CA, which enables man-in-the-middle attacks.
Record
- Researcher
- Chad Brubaker, Suman Jana, Baishakhi Ray, Sarfraz Khurshid and Vitaly Shmatikov
- Published by
- ieee-security.org
- Format
- Whitepaper
- Topic
- Crypto
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Chad Brubaker, Suman Jana, Baishakhi Ray, Sarfraz Khurshid and Vitaly Shmatikov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .