SSL trick certificate published

September 30, 2009 – 3:41 PM

On the Noisebridge hacker mailing list, security specialist Jacob Appelbaum has published an SSL certificate and pertinent private key that together allow web servers to avoid triggering an alert in vulnerable browsers – irrespective of the domain for which the certificate is submitted. Phishers, for example, could use the certificate to disguise their servers as legitimate banking servers – which would only be detectable by subjecting the certificate to closer scrutiny.

For his trick, Appelbaum modified the certificate according to the method demonstrated by Moxie Marlinspike at the Black Hat conference, entering a zero character (\0) in the name field (CN, Common Name).

Unlike Marlinspike, however, Appelbaum didn’t enter the zero between the domain name and the name of Marlinspike’s domain. Instead, he entered *\, effectively creating a wild card certificate for arbitrary domain names:

CN= *\
OU = Moxie Marlinspike Fan Club
O = Noisebridge
L = San Francisco
ST = California
C = US


