Web Hack List

Collected research

Vetting SSL Usage in Applications with SSLINT

SSLINT models correct SSL/TLS API usage as program dependence graph signatures and runs graph queries over C and C++ source, so an application that never validates a certificate or a hostname fails to match and is flagged. Applied to 381 Ubuntu packages it found 27 previously unknown flaws in mail, IRC, HTTP and database clients, all exploitable by a man in the middle.

Record

Researcher
Boyuan He, Vaibhav Rastogi, Yinzhi Cao, Yan Chen, V.N. Venkatakrishnan, Runqing Yang and Zhenrui Zhang
Published by
ieee-security.org
Format
Whitepaper
Topic
Crypto

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Boyuan He, Vaibhav Rastogi, Yinzhi Cao, Yan Chen, V.N. Venkatakrishnan, Runqing Yang and Zhenrui Zhang, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .