Black Hat : Hacking SSL with sslstrip | Internet News

Black Hat : Hacking SSL with sslstrip

Feb 18, 2009
1 minute read

blackhat.jpg

From the

think SSL is secure?

files:

WASHINGTON D.C We all rely on SSL and HTTPS to secure our web transactions. That’s why Moxie Marlinspike’s session at Black Hat DC on SSL/HTTPS attacks just blew my mind and has me ‘concerned’ to say the least.

Marlinspike demonstrated how a new tool he has developed called sslstrip – can trick browsers into thinking they are on an SSL/HTTPS secured site when in fact they are not.

The implication is that all the traffic from the regular HTTP site could then be easily collected by an attacker since the information is not secured.

“Lots of time the security of HTTPS comes down to the security of HTTP and HTTP is not secure,” Marlinspike told the capacity crowd.

Marlinspike is no stranger to getting around SSL security. In 2002 he released the -sslsniff – tool that could be used in a man in the middle attack to inject an illegitimate SSL certificate into an HTTP stream, tricking a user into thinking they were on an the legitimate SSL secured site (when in fact they were not).

So how do you protect yourself? Read more after the jump.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.