Talk With an Expert

Clickbait: Owning SSL via Heartbleed, POODLE, and Superfish

Clickbait: Owning SSL via Heartbleed, POODLE, and Superfish (PDF, 9.64MB)Published: 23 Dec, 2015
Created by:
SANS Institute
SANS Institute

In the twilight of SSL's effectiveness as a method of secure communication,demonstration of associated risk should be a vital portion of modern penetration testing. While SSL is broken, practical exploitation by security analysts is a confusing process. A holistic analysis of the Secure Socket Layer's attack surface can propel the development and adoption of practical strategies for vulnerability exploitation. Subsequent risk assessment, based on these processes, can drive enterprises to support higher levels of communications security within their organization. This paper will discuss tactics, techniques, and procedures targeted at leveraging SSL vulnerabilities within an information security assessment.

Meet the expert

SANS Institute
SANS Institute

SANS Institute

Launched in 1989 as a cooperative for information security thought leadership, it is SANS’ ongoing mission to empower cyber security professionals with the practical skills and knowledge they need to make our world a safer place.

Read more about SANS Institute