oss-sec mailing list archives

Re: STARTTLS vulnerabilities


From: Guido Berhoerster <guido+openwall.com () berhoerster name>
Date: Tue, 10 Aug 2021 15:41:56 +0200

Hi,

have you or are you planning to look into XMPP client/server
implementations as well?  The use of STARTTLS for both c2s and s2s
connections is still prevalent both in terms of implementation
support and actual practice and could potentially suffer form the
same issues (command injection or downgrade attacks).
-- 
Guido Berhoerster


Current thread: