Can you impersonate a client side cert??

From: Darren Craig (darren.craigat_private)
Date: Mon Jan 28 2002 - 03:59:41 PST

  • Next message: bluefur0r bluefur0r: "Dialup Banner Database?"

    Hi All,
    
    
    I have been reading a paper which was published back in Feb 2001 by a
    company call Sensepost which says that there is a way to impersonate a users
    client side cert by using the same common name. Does anybody have any
    experience of doing this or is it even possible considering that the users
    public part of the cert would be installed on the web server?
    
    Darren
    
    
    ******************************************************************
    Privileged, confidential and/or copyright information may
    be contained in this e-mail. This e-mail is for the use only 
    of the intended addressee. If you are not the intended 
    addressee, or the person responsible for delivering it to 
    the intended addressee, you may not copy, forward,
    disclose or otherwise use it or any part of it in any way 
    whatsoever, to do so is prohibited and may be unlawful.
    
    If you receive this e-mail by mistake please advise the 
    sender immediately by using the reply facility in your 
    e-mail software. Celare Limited may monitor the content
    of e-mails sent and received via its network for the purposes
    of ensuring compliance with its policies and procedures.
    
    This message is subject to and does not create or vary
    any contractual relationship between Celare Limited 
    and you.
    
    Thank you.
    ******************************************************************
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
    Service. For more information on SecurityFocus' SIA service which
    automatically alerts you to the latest security vulnerabilities please see:
    https://alerts.securityfocus.com/
    



    This archive was generated by hypermail 2b30 : Mon Jan 28 2002 - 09:42:31 PST