• Home
  • Blog
  • Projects
    • QWcrm
    • Joomla
      • mod_helloworld
      • plg_helloworld
      • QWRealURL
  • KB
    • Articles
    • Links
  • Forum
  • Stuff
    • Links
  • Search
  • Login
QuantumWarp QuantumWarp QuantumWarp
  • Home
  • Blog
  • Projects
    • QWcrm
    • Joomla
      • mod_helloworld
      • plg_helloworld
      • QWRealURL
  • KB
    • Articles
    • Links
  • Forum
  • Stuff
    • Links
  • Search
  • Home >
  • KB >
  • Links >
  • Web Server >
  • Articles >
  • SSL >
  • Extended Validation Certificates and MITM Attacks >
  • How to protect from man-in-the-middle attacks
Plusnet - Header Banner

How to protect from man-in-the-middle attacks

In light of a new man-in-the-middle type of attack unveiled this week at Black Hat D.C., VeriSign provides simple tips for end users and businesses.

The highlighted attack is the latest twist on the MITM attack, which relies on a user being fooled into going to the wrong Web site. What makes this attack different than previous MITM attacks is that the fraudulent site attempts to leverage false visual cues, namely replacing the fraudulent site's favicon with a padlock icon, which has traditionally been recognized as a visual cue to signify an SSL-protected site.

While this scheme is capable of reproducing the padlock, it is not capable of recreating the legitimate HTTPS indicator or the even more noticeable green glow in the address bar of high security Web browsers, where the site is secured with an Extended Validation SSL Certificate.

Listing Details

http://www.net-security.org/secworld.php?id=7087
Website
www.net-security.org/secworld.php?id=7087
Visited
131

Legal

  • Attribution
  • DMCA
  • Privacy & Cookies
  • Terms & Conditions

Resources

  • Feedback
  • Downloads
  • Typography

QuantumWarp

  • About
  • Contact

Follow Us

  • GitHub
© QuantumWarp 2020, Powered by Astroid. Developed by QuantumWarp