oss-sec mailing list archives
Re: STARTTLS vulnerabilities
From: Guido Berhoerster <guido+openwall.com () berhoerster name>
Date: Tue, 10 Aug 2021 15:41:56 +0200
Hi, have you or are you planning to look into XMPP client/server implementations as well? The use of STARTTLS for both c2s and s2s connections is still prevalent both in terms of implementation support and actual practice and could potentially suffer form the same issues (command injection or downgrade attacks). -- Guido Berhoerster
Current thread:
- STARTTLS vulnerabilities Hanno Böck (Aug 10)
- Re: STARTTLS vulnerabilities Guido Berhoerster (Aug 10)
- Re: STARTTLS vulnerabilities Hanno Böck (Aug 10)
- Re: STARTTLS vulnerabilities Eric Blake (Aug 11)
- Re: STARTTLS vulnerabilities Hanno Böck (Aug 11)
- Re: STARTTLS vulnerabilities Eric Blake (Aug 16)
- Re: STARTTLS vulnerabilities Eric Blake (Aug 18)
- Re: STARTTLS vulnerabilities Hanno Böck (Aug 10)
- Re: STARTTLS vulnerabilities Guido Berhoerster (Aug 10)
- Re: STARTTLS vulnerabilities Hanno Böck (Aug 11)
- Re: STARTTLS vulnerabilities Matthew Wild (Aug 11)