Page 1 of 1

Certificate exploit test.

Posted: Fri Jan 17, 2020 9:12 am
by Passenger
http://testcve.kudelskisecurity.com/
The CVE-2020-0601 requires that the original CA certificate is in your certificate cache, this website is using JS to load an example page using the correct certificate and will then redirect you to a webpage serving a fake, crafted certificate.

If you see "Hello World" on the next screen, you're vulnerable to CVE-2020-0601.

If you get a certificate error, you're safe!
Slimjet passes the test and in fact intercepts the certificate error with an informative error screen. :mrgreen:

Re: Certificate exploit test.

Posted: Sun Feb 23, 2020 6:41 pm
by slimjet1