Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20140307085615.GA23180@openwall.com>
Date: Fri, 7 Mar 2014 12:56:15 +0400
From: Solar Designer <solar@...nwall.com>
To: oss-security@...ts.openwall.com
Subject: Re: IMAP STARTTLS sniff tool

Hi,

On Fri, Mar 07, 2014 at 09:37:01AM +0100, Bob Ezrin wrote:
> Hi all. We managed succesfully to sniff inside POP3S, SMTPS, IMAPS & HTTPS tunnels using arpspoof, iptables & sslsplit to make MITM. Now we want to sniff inside STARTTLS tunnels (specifically IMAP) but unfortunately sslsplit doesn't supports STARTTLS. Is there/do you know another SSL/TLS tool supporting IMAP over STARTTLS to make MITM? Many thanks B.

Sorry for not addressing your (mostly off-topic) question directly (I
don't know the answer), but it got me wondering what the most
appropriate mailing list would be for this sort of topics.  We mostly
haven't been using the oss-security list for such topics so far, and it
is unclear whether such broader scope is desirable or not.  In part,
this might depend on whether there exists a more suitable list or not.

I'd think that maybe the Penetration Testing list could be it:

http://www.securityfocus.com/archive/101/description
http://seclists.org/pen-test/

but it appears rather inactive lately.  Yet I think it's worth posting
the question in there, at least to see if the list is currently usable
(would anyone reply?)  Bob, can you try that?

Opinions?

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.