摘要
SSL是在互联网上提供安全通讯的密码学协议。在分析SSL协议和中间人攻击原理的基础上,利用OpenSSL开发库实现了中间人攻击,包括会话劫持、公钥证书的伪造和数据的转发,为用户安全使用SSL协议提供了建议和参考。
SSL was a cryptograiphic protocol that provides secure communications on the lnternet. This paper first analysed the principle of SSL protocol and man--in--the--middle attack, then introduced how to implemente man--in--the-middle Attack using OpenSSL Library, including Session Hijack, falsification of X.509 digital certificate and relayed messages between victims. The experiment provided recommendations and reference for clients using SSL protocol in security.
出处
《计算机安全》
2009年第3期69-72,共4页
Network & Computer Security
作者简介
陈昱(1981-),男,福州大学软件学院,助教,硕士,主要从事密码学与信息安全,Web,并行计算与可视化方面的研究。