Re: how can you verify that the site you get is not a fake?

From: Felipe Alfaro Solana (felipe.alfaro_at_gmail.com)
Date: 06/06/05

  • Next message: Dotan Cohen: "Re: Problem installing azureus"
    Date: Mon, 6 Jun 2005 15:38:58 +0200
    To: For users of Fedora Core releases <fedora-list@redhat.com>
    
    

    On 6/6/05, Matthew Miller <mattdm@mattdm.org> wrote:
    > On Mon, Jun 06, 2005 at 06:05:58AM -0700, bruce wrote:
    > > but you still haven't addressed my problem/issue/question...
    > > and that's how do i as a user (not an app) know that this is the right
    > > site for the url i entered... my fear is that a malicious site, could
    > > simply fake the information he's providing, to 'look' like the actual/real
    > > site...
    > > and as of yet.. i can't craft a solution to this issue...
    >
    > You could trust us that it's very hard to fake the SSL information, and then
    > you could inspect that. (Double click on the little lock icon.) You'll see
    > something like:
    >
    > Web Site Identity Verified
    >
    > The web site www.bu.edu supports authentication for the page you are
    > viewing. The identity of this web site has been verified by Thawte
    > Consulting cc, a certificate authority you trust for this purpose.
    >
    >
    > In the Firefox advanced preferences, you can manage which certificate
    > authorities you trust.

    Nah! That's not enough... many web browsers are vulnerable to
    cross-site scripting code. I've seen some real proof-of-concept web
    sites that, by using a main frame protected via HTTP/S and a valid SSL
    certificate, where vulnerable to cross-site scripting-like attacks
    that were able to insert fake pages into a subframe without the web
    browser even alerting about it.

    SSL is very good, but poor implementations of web browsers, protocols,
    and the end-user itself make it far from the perfect solution.

    So the answer is: you really can't be sure 100% the site you're seeing
    is really the site you're expecting to see. To alleviate the problem,
    always enter the URL manually on your web browser, check the SSL
    certificate, the CA that signed the SSL certificate and the IP address
    of the target machine.

    -- 
    fedora-list mailing list
    fedora-list@redhat.com
    To unsubscribe: http://www.redhat.com/mailman/listinfo/fedora-list
    

  • Next message: Dotan Cohen: "Re: Problem installing azureus"

    Relevant Pages

    • Re: Publish SSL Web Server behind SBS2003
      ... > How to configure a certificate for use with a Web publishing rule in ISA ... > Server 2004 ... > RWW/OWA for SSL encryption. ... Right click the SSL Web Site and click Properties. ...
      (microsoft.public.windows.server.sbs)
    • RE: can I create a new certificate on ISA 2004/SBS 2003
      ... by default the SSL website such as OWA/RWW is bound to ... the predefined certificate issued by the CEICW Wizard. ... expand the Web Sites node and click the SSL Web Site. ... Microsoft CSS Online Newsgroup Support ...
      (microsoft.public.windows.server.sbs)
    • Multiple Web Hosting Problems
      ... You cannot use SSL and Host Headers together because ... of the site imbedded in them, so one certificate can only ... >setting the New Web site up IIS with my Internal IP ...
      (microsoft.public.windows.server.sbs)
    • RE: configuring ssl certificate in multiple website
      ... We can perform follow steps to configure one SSL web site: ... Prepare certificate for this SSL web site ... IIS SSL Configuration Component ...
      (microsoft.public.windows.server.sbs)
    • RE: SSL - Man-in-the-Middle filtering
      ... Isn't this an interference in an encrypted communication, ... how can you trust the confidentiality this ... Subject: SSL - Man-in-the-Middle filtering ... no longer see the actual CA of server certificate). ...
      (Focus-IDS)