Full Disclosure mailing list archives

SSL vulnerability


From: "Daniel Sichel" <daniels () Ponderosatel com>
Date: Wed, 3 Mar 2004 09:07:08 -0800

I am a Sidewinder G2 user. In their latest upgrade they are going away
from an IPSEC based VPN client to SSL. If memory servers me there are
some exploitable issues in SSL. SecureComputing uses a proprietary OS
based on SecureOS based on OpenBSD. I am not sure what flavor of SSL
they use, but I am guessing it's based on Open SSL.
I know this is the right place to ask, so.... What have you folks heard
about recent SSL vulnerabilites, how easy are they to exploit, and are
there any known exploits recently?

Thanks
Dan Sichel

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: