Displaying 2 results from an estimated 2 matches for "x00www".
Did you mean:
x00w
2015 Apr 08
0
AST-2015-003: TLS Certificate Common name NULL byte exploit
...ntaining a null byte
after the portion of the common name that Asterisk expected. For
example, if Asterisk is trying to register to www.domain.com,
Asterisk will accept certificates of the form
www.domain.com\x00www.someotherdomain.com - for more information
on this exploit, see
https://fotisl.com/blog/2009/10/the-null-certificate-prefix-bug/
Resolution Asterisk has been patched to verify that the common name...
2015 Apr 08
0
AST-2015-003: TLS Certificate Common name NULL byte exploit
...ntaining a null byte
after the portion of the common name that Asterisk expected. For
example, if Asterisk is trying to register to www.domain.com,
Asterisk will accept certificates of the form
www.domain.com\x00www.someotherdomain.com - for more information
on this exploit, see
https://fotisl.com/blog/2009/10/the-null-certificate-prefix-bug/
Resolution Asterisk has been patched to verify that the common name...