[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <5c96516b0909111033g44eeabd1ibedb41d3f679adff@mail.gmail.com>
Date: Fri, 11 Sep 2009 12:33:33 -0500
From: Bill Borskey <wborskey@...il.com>
To: bugtraq@...urityfocus.com
Subject: iphone email client does not validate ssl certificates
Info:
iPod/iPhone standard e-mail application does not validate SSL certificates
and is vulnerable to a MITM (man in the middle attack).
Vulnerable: All versions.
Discovered by: William Borskey wborskey@...il.com
Discussion:
The mail application that ships with the iPod/iPhone does not validate SSL
certificates. A malicious user can use software such as ettercap-ng to sniff
email passwords without the application warning the victim that the
certificate may be invalid.
Exploit:
This flaw can be exploited with ettercap-ng.
Powered by blists - more mailing lists