Microsoft/Phishing SSLFail!

Posted by romain on January 16, 2009
SSL Fail Images, SSLFail

phishing_microsoft

2 Comments to Microsoft/Phishing SSLFail!

[...] recently had a link submitted (Thanks Jirka) that I think is a great example of betraying user trust in the SSL Realm. The link [...]

Jirka Vejrazka
January 20, 2009

OK, I did a bit more digging and found out that MSIE does not even blink when accessing the site (I used Firefox for the first test). Turns out that the SSL certificate has multiple Common Names in it, which MSIE can cope with but Firefox can’t.

Reading RFC2818, I got the impression that MSIE got it right here. I stand corrected.

Leave a comment

WP_Big_City