Web Hack List

Later archive addition

Using Frankencerts for Automated Adversarial Testing of Certificate Validation in SSL/TLS Implementations

Generates frankencerts by randomly mutating parts of millions of real X.509 certificates, then differentially tests eight SSL/TLS libraries against each other so that any disagreement flags a validation bug. Found 208 discrepancies, including MatrixSSL and GnuTLS accepting any valid X.509v1 certificate as a CA, which enables man-in-the-middle attacks.

Record

Researcher
Chad Brubaker, Suman Jana, Baishakhi Ray, Sarfraz Khurshid and Vitaly Shmatikov
Format
Whitepaper

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Chad Brubaker, Suman Jana, Baishakhi Ray, Sarfraz Khurshid and Vitaly Shmatikov, first published at the original source. Preserved copies are kept so the citation survives its host.