etax 2010 failure to validate remote ssl certificate properly

看板Bugtraq作者時間15年前 (2010/09/09 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
etax 2010[0] 1.fails to properly check the remote https server has a valid certificate for the host it claims to be from. Test case: edit the hosts file like this: IP_OF_HTTPS_SERVER_HERE etaxservices10.etax.ato.gov.au e.g. 203.0.178.114 (note: you need a certificate for _any_ domain signed by a CA installed on the client boxen). 2. will communicate over http if told to ;) (mod_rewrite etc.). .... etax 2010 will send the details of the tax request in a SOAP request. Have fun ;) [0] http://www.ato.gov.au/individuals/content.asp?doc=/content/32234.htm&page=5 -- Small things make base men proud. -- William Shakespeare, "Henry VI"
文章代碼(AID): #1CXyzYjJ (Bugtraq)