moxie-marlinspike
Basically when these vulnerable browsers check the domain name contained in the attacker’s certificate, they stop reading any characters that follow the “\0″ in the name. More significantly, an attacker can also register a wildcard domain, such as *\0.badguy.com, which would then give him a certificate that would allow him to masquerade as any site on the internet and intercept communication.
- Web annotation on Vulnerabilities Allow Attacker to Impersonate Any Website | Threat Level | Wired.com

Share this annotation

Post to Basecamp Project Update Twitter Bookmark on Del.icio.us Send E-mail Post to a Blog Post to Backpack Post to Trac Post to Bugzilla Post to a Tumblr Update Friendfeed Posterous

paste in your blog
 
paste anywhere: IM, mail
 
give this link to a friend
 

Tags: jul_09, wired.com, annotations
Comments are allowed
This copy is published

Note: "This copy is kept-secret" would mean its URL is not published, but anyone knowing its URL can still view it.