[Bug 1380038] [NEW] SSL problems: doesn't check certificate chain and hostname when ssl connecting

2014-10-11 Thread rainkin
*** This bug is a security vulnerability *** Public security bug reported: Recently, we are trying to find SSL security problems by static analysis. For example, as we all know, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or

[Bug 1376592] [NEW] X509 certificate verification problem

2014-10-02 Thread rainkin
Public bug reported: Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or to misunderstand the APIs when using SSL/TLS, which might cause severe man in the middle attack and break the entire TLS mechanism. We believe that

[Bug 1376595] [NEW] X509 certificate verification problem

2014-10-02 Thread rainkin
Public bug reported: Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or to misunderstand the APIs when using SSL/TLS, which might cause severe man in the middle attack and break the entire TLS mechanism. We believe that scrollz

[Bug 1376601] [NEW] X509 certificate verification problem

2014-10-02 Thread rainkin
Public bug reported: Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or to misunderstand the APIs when using SSL/TLS, which might cause severe man in the middle attack and break the entire TLS mechanism. We believe that

[Bug 1381936] [NEW] SSL connection is not secure in links

2014-10-16 Thread rainkin
*** This bug is a security vulnerability *** Public security bug reported: Recently, we are trying to find SSL security problems by static analysis. For example, as we all know, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or

[Bug 1381940] [NEW] suck have ssl security problems

2014-10-16 Thread rainkin
*** This bug is a security vulnerability *** Public security bug reported: Recently, we are trying to find SSL security problems by static analysis. For example, as we all know, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or

[Bug 1381936] Re: SSL connection is not secure in links

2014-10-17 Thread rainkin
I am very glad to receive your responce. We test links in Ubuntu 12.04. thanks, rainkin -- 原始邮件 -- 发件人: Axel Beckert;a...@debian.org; 发送时间: 2014年10月18日(星期六) 凌晨2:51 收件人: rainkin598105...@qq.com; 主题: [Bug 1381936] Re: SSL connection is not secure in links

[Bug 1380298] Re: some SSL security problems

2014-10-19 Thread rainkin
** Description changed: - Recently, we are trying to find SSL security problems by static - analysis. For example, as we all know, Hostname verification is an - important step when verifying X509 certificates, however, people tend to - miss the step or to misunderstand the APIs when using

[Bug 1380304] Re: perdition have some SSL security problems

2014-10-19 Thread rainkin
** Description changed: - Recently, we are trying to find SSL security problems by static - analysis. For example, as we all know, Hostname verification is an - important step when verifying X509 certificates, however, people tend to - miss the step or to misunderstand the APIs when using

[Bug 1380435] Re: epic5's SSL connection is not secure

2014-10-19 Thread rainkin
to simulate the DNS hijack - 46.137.23.30 attacker.com -(46.137.23.30 is a normal irc server) - - 2. #rainkin@rainkin:~$ epic5 rainkin attacker.com:6697:::OPN:irc-ssl - - 3. result : succeed!!! - - The fetch succeeded, indicating the software didn't check the hostname - against

[Bug 1380304] Re: perdition have some SSL security problems

2014-10-19 Thread rainkin
** Description changed: Recently, our group is trying to find SSL security problems by static analysis. When using Openssl, people tend to miss the step or to misunderstand the APIs when using SSL/TLS, which might cause severe man in the middle attack and break the entire TLS mechanism.

[Bug 1380435] Re: epic5's SSL connection is not secure

2014-10-19 Thread rainkin
** Description changed: Recently, our group is trying to find SSL security problems by static analysis. When using Openssl, people tend to miss the step or to misunderstand the APIs when using SSL/TLS, which might cause severe man in the middle attack and break the entire TLS mechanism.

[Bug 1380298] Re: some SSL security problems

2014-10-19 Thread rainkin
** Description changed: Recently, our group is trying to find SSL security problems by static analysis. When using Openssl, people tend to miss the step or to misunderstand the APIs when using SSL/TLS, which might cause severe man in the middle attack and break the entire TLS mechanism.

[Bug 1380458] Re: dma have some SSL security problems

2014-10-19 Thread rainkin
** Description changed: - Recently, we are trying to find SSL security problems by static - analysis. For example, as we all know, Hostname verification is an - important step when verifying X509 certificates, however, people tend to - miss the step or to misunderstand the APIs when using

[Bug 1380439] Re: ftp-ssl's ssl connection is not secure

2014-10-19 Thread rainkin
** Description changed: - Recently, we are trying to find SSL security problems by static - analysis. For example, as we all know, Hostname verification is an - important step when verifying X509 certificates, however, people tend to - miss the step or to misunderstand the APIs when using

[Bug 1380453] Re: epic4 have some SSL security problems

2014-10-19 Thread rainkin
the software manually. 一.Hostname verification 1. change /etc/hosts in order to simulate the DNS hijack - 46.137.23.30 attacker.com -(46.137.23.30 is a normal irc server) + 46.137.23.30 attacker.com +    (46.137.23.30 is a normal irc server) 2. #rainkin@rainkin:~$ epic4 rainkin

[Bug 1380439] Re: ftp-ssl's ssl connection is not secure

2014-10-19 Thread rainkin
** Description changed: Recently, our group is trying to find SSL security problems by static analysis. When using Openssl, people tend to miss the step or to misunderstand the APIs when using SSL/TLS, which might cause severe man in the middle attack and break the entire TLS mechanism.

[Bug 1380449] Re: citadel-client have some ssl security problems

2014-10-19 Thread rainkin
** Description changed: - Recently, we are trying to find SSL security problems by static - analysis. For example, as we all know, Hostname verification is an - important step when verifying X509 certificates, however, people tend to - miss the step or to misunderstand the APIs when using

[Bug 1380452] Re: apf-client doesn't check hostname or expired time when verifying x509 certificate

2014-10-19 Thread rainkin
** Description changed: - Recently, we are trying to find SSL security problems by static - analysis. For example, as we all know, Hostname verification is an - important step when verifying X509 certificates, however, people tend to - miss the step or to misunderstand the APIs when using

[Bug 1381936] Re: SSL connection is not secure in links

2014-10-19 Thread rainkin
** Description changed: - Recently, we are trying to find SSL security problems by static - analysis. For example, as we all know, Hostname verification is an - important step when verifying X509 certificates, however, people tend to - miss the step or to misunderstand the APIs when using

[Bug 1381940] Re: suck have ssl security problems

2014-10-19 Thread rainkin
** Description changed: - Recently, we are trying to find SSL security problems by static - analysis. For example, as we all know, Hostname verification is an - important step when verifying X509 certificates, however, people tend to - miss the step or to misunderstand the APIs when using

[Bug 1378617] [NEW] xxxterm has SSL security problems

2014-10-07 Thread rainkin
Public bug reported: Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or to misunderstand the APIs when using SSL/TLS, which might cause severe man in the middle attack and break the entire TLS mechanism. We believe that xxxterm

[Bug 1380022] [NEW] aiccu's SSL connection is not secure

2014-10-11 Thread rainkin
*** This bug is a security vulnerability *** Public security bug reported: Recently, we are trying to find SSL security problems by static analysis. For example, as we all know, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or

[Bug 1376592] Re: X509 certificate verification problem

2014-10-11 Thread rainkin
** Information type changed from Public to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1376592 Title: X509 certificate verification problem To manage notifications about this bug

[Bug 1378617] Re: xxxterm has SSL security problems

2014-10-11 Thread rainkin
** Information type changed from Public to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1378617 Title: xxxterm has SSL security problems To manage notifications about this bug go

[Bug 1376595] Re: X509 certificate verification problem

2014-10-11 Thread rainkin
** Information type changed from Public to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1376595 Title: X509 certificate verification problem To manage notifications about this bug

[Bug 1380022] Re: aiccu's SSL connection is not secure

2014-10-11 Thread rainkin
** Description changed: Recently, we are trying to find SSL security problems by static analysis. For example, as we all know, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or to misunderstand the APIs when using

[Bug 1380031] [NEW] hostname and certificate chain check missing when verifying X509 certificate

2014-10-11 Thread rainkin
*** This bug is a security vulnerability *** Public security bug reported: Recently, we are trying to find SSL security problems by static analysis. For example, as we all know, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or

[Bug 1376592] Re: X509 certificate verification problem

2014-10-11 Thread rainkin
** Description changed: - Hostname verification is an important step when verifying X509 - certificates, however, people tend to miss the step or to misunderstand - the APIs when using SSL/TLS, which might cause severe man in the middle - attack and break the entire TLS mechanism. - We believe

[Bug 1376595] Re: X509 certificate verification problem

2014-10-11 Thread rainkin
** Description changed: - Hostname verification is an important step when verifying X509 - certificates, however, people tend to miss the step or to misunderstand - the APIs when using SSL/TLS, which might cause severe man in the middle - attack and break the entire TLS mechanism. + Recently, we

[Bug 1376592] Re: X509 certificate verification problem

2014-10-11 Thread rainkin
** Description changed: Recently, we are trying to find SSL security problems by static anaylsis. For example, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or to misunderstand the APIs when using SSL/TLS, which might

[Bug 1376595] Re: X509 certificate verification problem

2014-10-11 Thread rainkin
** Description changed: Recently, we are trying to find SSL security problems by static anaylsis. For example, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or to misunderstand the APIs when using SSL/TLS, which might

[Bug 1380035] [NEW] scrollz doesn't check hostanem and expired time when verifying x509 certificate

2014-10-11 Thread rainkin
*** This bug is a security vulnerability *** Public security bug reported: Recently, we are trying to find SSL security problems by static anaylsis. For example, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or to

[Bug 1376595] Re: xface4-mailwatch-plugin have some SSL security problems

2014-10-11 Thread rainkin
** Description changed: Recently, we are trying to find SSL security problems by static anaylsis. For example, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or to misunderstand the APIs when using SSL/TLS, which might

[Bug 1378617] Re: xxxterm has SSL security problems

2014-10-11 Thread rainkin
** Description changed: - Hostname verification is an important step when verifying X509 - certificates, however, people tend to miss the step or to misunderstand - the APIs when using SSL/TLS, which might cause severe man in the middle - attack and break the entire TLS mechanism. + Recently, we

[Bug 1380039] [NEW] pacemaker-mgmt doesn't chekc expired time and hostname when ssl connecting

2014-10-11 Thread rainkin
*** This bug is a security vulnerability *** Public security bug reported: Recently, we are trying to find SSL security problems by static analysis. For example, as we all know, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or

[Bug 1380038] [NEW] SSL problems: doesn't check certificate chain and hostname when ssl connecting

2014-10-11 Thread rainkin
*** This bug is a security vulnerability *** Public security bug reported: Recently, we are trying to find SSL security problems by static analysis. For example, as we all know, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or

[Bug 1380298] [NEW] some SSL security problems

2014-10-12 Thread rainkin
*** This bug is a security vulnerability *** Public security bug reported: Recently, we are trying to find SSL security problems by static analysis. For example, as we all know, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or

[Bug 1380304] Re: perdition have some SSL security problems

2014-10-12 Thread rainkin
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1380304 Title: perdition have some SSL security problems To manage notifications

[Bug 1380435] [NEW] epic5's SSL connection is not secure

2014-10-12 Thread rainkin
*** This bug is a security vulnerability *** Public security bug reported: Recently, we are trying to find SSL security problems by static analysis. For example, as we all know, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or

[Bug 1380435] Re: epic5's SSL connection is not secure

2014-10-12 Thread rainkin
is a normal irc server) + + 2. #rainkin@rainkin:~$ epic5 rainkin attacker.com:6697:::OPN:irc-ssl + + 3. result : succeed!!! + + The fetch succeeded, indicating the software didn't check the hostname + against the signee of the certificate. + + 二. Also for expired time check, + 1. change

[Bug 1380439] [NEW] ftp-ssl's ssl connection is not secure

2014-10-12 Thread rainkin
*** This bug is a security vulnerability *** Public security bug reported: Recently, we are trying to find SSL security problems by static analysis. For example, as we all know, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or

[Bug 1380449] [NEW] citadel-client have some ssl security problems

2014-10-12 Thread rainkin
*** This bug is a security vulnerability *** Public security bug reported: Recently, we are trying to find SSL security problems by static analysis. For example, as we all know, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or

[Bug 1380452] [NEW] apf-client doesn't check hostname or expired time when verifying x509 certificate

2014-10-12 Thread rainkin
*** This bug is a security vulnerability *** Public security bug reported: Recently, we are trying to find SSL security problems by static analysis. For example, as we all know, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or

[Bug 1380453] [NEW] epic4 have some SSL security problems

2014-10-12 Thread rainkin
the software manually. 一.Hostname verification 1. change /etc/hosts in order to simulate the DNS hijack 46.137.23.30 attacker.com (46.137.23.30 is a normal irc server) 2. #rainkin@rainkin:~$ epic4 rainkin attacker.com:6697:::OPN:irc-ssl 3. result : succeed!!! The fetch succeeded

[Bug 1380458] Re: dma have some SSL security problems

2014-10-12 Thread rainkin
** Attachment added: wireshark ssl conneting packages https://bugs.launchpad.net/ubuntu/+source/dma/+bug/1380458/+attachment/4233649/+files/dma.zip -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1380458] [NEW] dma have some SSL security problems

2014-10-12 Thread rainkin
*** This bug is a security vulnerability *** Public security bug reported: Recently, we are trying to find SSL security problems by static analysis. For example, as we all know, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or

[Bug 1380304] Re: perdition have some SSL security problems

2014-10-12 Thread rainkin
** Description changed: Recently, we are trying to find SSL security problems by static analysis. For example, as we all know, Hostname verification is an important step when verifying X509 certificates, however, people tend to miss the step or to misunderstand the APIs when using