AOH :: HP Unsorted A :: BT-21230.HTM

aMSN SSL Certificate Vulnerability



aMSN SSL Certificate Vulnerability
aMSN SSL Certificate Vulnerability



aMSN SSL Certificate Vulnerability

I. The Vulnerability

aMSN does not check SSL certificate before sending MSN user
credentials. An attacker is able to obtain MSN username and password
with a spoofed certificate and no alert is generated to the user.
This vulnerability was found in aMSN 0.97.2. Other versions may also
be affected.

II. Disclosure Timeline

06/19/2009 - Vendor contact.
06/26/2009 - No answer. Public Disclosure.

III. Vendor

http://www.amsn-project.net/ 

IV. Credit

Gabriel Menezes Nunes 

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.