iphone email client does not validate ssl certificates

看板Bugtraq作者時間16年前 (2009/09/12 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/3 (看更多)
Info: iPod/iPhone standard e-mail application does not validate SSL certificates and is vulnerable to a MITM (man in the middle attack). Vulnerable: All versions. Discovered by: William Borskey wborskey@gmail.com Discussion: The mail application that ships with the iPod/iPhone does not validate SSL certificates. A malicious user can use software such as ettercap-ng to sniff email passwords without the application warning the victim that the certificate may be invalid. Exploit: This flaw can be exploited with ettercap-ng.
文章代碼(AID): #1Agf1YK9 (Bugtraq)
文章代碼(AID): #1Agf1YK9 (Bugtraq)