Web Hack List

Later archive addition

Creating a Rogue CA Certificate

Announcement of the 25C3 result in which an MD5 chosen-prefix collision was used against a commercial CA still signing with MD5, producing a rogue intermediate CA certificate trusted by every common browser. It can impersonate any HTTPS site, making phishing against banking undetectable. Links the write-up, slides, colliding certificates and a demo site.

Record

Researcher
Alexander Sotirov, Marc Stevens, Jacob Appelbaum, Arjen Lenstra, David Molnar, Dag Arne Osvik and Benne de Weger

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Alexander Sotirov, Marc Stevens, Jacob Appelbaum, Arjen Lenstra, David Molnar, Dag Arne Osvik and Benne de Weger, first published at the original source. Preserved copies are kept so the citation survives its host.