Collected research
Vetting SSL Usage in Applications with SSLINT
SSLINT models correct SSL/TLS API usage as program dependence graph signatures and runs graph queries over C and C++ source, so an application that never validates a certificate or a hostname fails to match and is flagged. Applied to 381 Ubuntu packages it found 27 previously unknown flaws in mail, IRC, HTTP and database clients, all exploitable by a man in the middle.
Record
- Researcher
- Boyuan He, Vaibhav Rastogi, Yinzhi Cao, Yan Chen, V.N. Venkatakrishnan, Runqing Yang and Zhenrui Zhang
- Published by
- ieee-security.org
- Format
- Whitepaper
- Topic
- Crypto
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Boyuan He, Vaibhav Rastogi, Yinzhi Cao, Yan Chen, V.N. Venkatakrishnan, Runqing Yang and Zhenrui Zhang, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .