Oleh Symbolic Software ditemukan oleh Player FM dan komunitas kami — hak cipta dimiliki oleh penerbit, bukan Player FM, dan audio langsung didapatkan dari server mereka. Tekan tombol Berlangganan untuk mendapat setiap pembaharuan di Player FM, atau salin URL feed ke aplikasi podcast lainnya.

Orang-orang menyukai kami!

Ulasan pengguna

"Suka fungsi offline"
"Inilah "cara" untuk menangani langganan podcast Anda. Ini juga cara yang bagus untuk menemukan podcast baru."

Episode 19: Cross-Protocol Attacks on TLS with ALPACA!

41:44
 
Bagikan
 

Manage episode 297290119 series 2936005
Oleh Symbolic Software ditemukan oleh Player FM dan komunitas kami — hak cipta dimiliki oleh penerbit, bukan Player FM, dan audio langsung didapatkan dari server mereka. Tekan tombol Berlangganan untuk mendapat setiap pembaharuan di Player FM, atau salin URL feed ke aplikasi podcast lainnya.

TLS is an internet standard to secure the communication between servers and clients on the internet, for example that of web servers, FTP servers, and Email servers. This is possible because TLS was designed to be application layer independent, which allows its use in many diverse communication protocols.

ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. Attackers can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.

Links and papers discussed in the show:

Music composed by Toby Fox and performed by Sean Schafianski.

Special Guests: Marcus Brinkmann and Robert Merget.

Sponsored By:

Links:

  continue reading

24 episode

Bagikan
 
Manage episode 297290119 series 2936005
Oleh Symbolic Software ditemukan oleh Player FM dan komunitas kami — hak cipta dimiliki oleh penerbit, bukan Player FM, dan audio langsung didapatkan dari server mereka. Tekan tombol Berlangganan untuk mendapat setiap pembaharuan di Player FM, atau salin URL feed ke aplikasi podcast lainnya.

TLS is an internet standard to secure the communication between servers and clients on the internet, for example that of web servers, FTP servers, and Email servers. This is possible because TLS was designed to be application layer independent, which allows its use in many diverse communication protocols.

ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. Attackers can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.

Links and papers discussed in the show:

Music composed by Toby Fox and performed by Sean Schafianski.

Special Guests: Marcus Brinkmann and Robert Merget.

Sponsored By:

Links:

  continue reading

24 episode

Semua episode

×
 
Loading …

Selamat datang di Player FM!

Player FM memindai web untuk mencari podcast berkualitas tinggi untuk Anda nikmati saat ini. Ini adalah aplikasi podcast terbaik dan bekerja untuk Android, iPhone, dan web. Daftar untuk menyinkronkan langganan di seluruh perangkat.

 

Player FM - Aplikasi Podcast
Offline dengan aplikasi Player FM !

Panduan Referensi Cepat