If you think you're safe from man-in-the-middle (MITM) attacks as long as you're visiting an Extended Validation SSL (EV SSL) site, then think again: Researchers will release a new tool at Black Hat USA later this month that lets an attacker hack into a user's session on an EV SSL-secured site. . Mike Zusman and Alex Sotirov -- who in March first demonstrated possible MITM attacks on EV SSL at CanSecWest -- will release for the first time their proxy tool at the Las Vegas conference, as well as demonstrate variations on the attacks they have discovered. The Python-based tool can launch an attack even with the secure green badge displaying on the screen: "It doesn't alert the user that anything fishy is going on," says Zusman, principal consultant at Intrepidus. The link for this article located at Dark Reading is no longer available. . Experts set to demonstrate a covert method for intercepting EV SSL transactions during Black Hat USA, evading detection mechanisms.. EV SSL, session Hijacking, cybersecurity Threats, security Tools. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.