Try our new Certificate Revocation List Check Tool
CRLcheck.exe is a tool developed to verify digital signatures of executable files. It collects files from known paths on your client, checks their signature, and checks Certificate Revocation Lists (CRL) and OCSP download. This helps avoid delays in launching files.
Category published:  Exchange 2007 Exchange 2010   Click on the Category button to get more articles regarding that product.

Man in the Middle SSL-Self Signed Attack Exchange 2007/2010

Posted by admin on 13.10.2012

Windows Mobile is the only mobile device range which is not cheatable with the man in the middle SSL-Spoof.

IOS 5 and current Android may be unsafe currently if you use self signed SSL Cert for the Activesync IIS Site.

Explained For non IT-managers (people who pay IT people and reduce their budget)

1) If you are a Small Business
2) You run Exchange 2003/2007/2010 SBS
3) You don’t want to invest in a official SA/UC certificate
4) You internal Administrator has come up with an inexpensive solution of Self Signed SSL (because you dont’ want to spend USD 300.- per year)
5) Your employee visits a hotel or meeting room with a faked free WIFI (A hacker does a man in the middle split). He checks mail with his Iphone.
6) The IPHOEN or Android connets to the fakes exchange / the hacker sniffs the traffic.
7) Hacker sens Remote wipe signal
8) Your mobile data is gone

  

http://www.wpcentral.com/windows-phone-dodges-black-hat-2012-certificate-vulnerability

http://www.blackhat.com/usa/bh-us-12-briefings.html

http://searchsecurity.techtarget.com/news/2240160456/Black-Hat-2012-SSL-handling-weakness-leads-to-remote-wipe-hack

 


 Category published:  Exchange 2007 Exchange 2010   Click on the Category button to get more articles regarding that product.