BugTraq
iphone email client does not validate ssl certificates Sep 11 2009 05:33PM
Bill Borskey (wborskey gmail com) (1 replies)
Info:

iPod/iPhone standard e-mail application does not validate SSL certificates
and is vulnerable to a MITM (man in the middle attack).

Vulnerable: All versions.

Discovered by: William Borskey wborskey (at) gmail (dot) com [email concealed]

Discussion:

The mail application that ships with the iPod/iPhone does not validate SSL
certificates. A malicious user can use software such as ettercap-ng to sniff
email passwords without the application warning the victim that the
certificate may be invalid.

Exploit:

This flaw can be exploited with ettercap-ng.

[ reply ]
Re: iphone email client does not validate ssl certificates Sep 26 2009 09:54AM
Pavel Machek (pavel ucw cz) (1 replies)
Re: iphone email client does not validate ssl certificates Sep 29 2009 01:27AM
Steve Shockley (steve shockley shockley net)


 

Privacy Statement
Copyright 2010, SecurityFocus