What Is SSL Sniffing? How Do You Prevent SSL Sniffing? - PowerPoint PPT Presentation

About This Presentation
Title:

What Is SSL Sniffing? How Do You Prevent SSL Sniffing?

Description:

Understand what is SSL Sniffing and know how to prevent it. SecureBox provides the Best Anti SSL Sniffing software which ensure your protection against cyber threats. Get Free Now! – PowerPoint PPT presentation

Number of Views:11
Slides: 12
Provided by: lindawilsonjv
Category:
Tags:

less

Transcript and Presenter's Notes

Title: What Is SSL Sniffing? How Do You Prevent SSL Sniffing?


1
What Is SSL Sniffing?
  • Thwart Sniff With HTTPS or SSL Certificates by
    securebox.comodo.com

2
Definition What IS SSL Sniffing?
  • SSL sniffing alludes to the capturing and
    perusing of SSL encoded traffic utilizing a MITM
    (Man in the Middle) intermediary.
  • Hackers can utilize this to take touchy
    information from any framework/arrange or to do
    dynamic spying and capture private associations
    and correspondences.

3
What are SSL Certificates?
  • SSL (Secure Sockets Layer) testaments are
    utilized to verify online correspondence and
    exchanges with encryption.
  • The SSL encryption innovation makes encoded
    associations between a client/internet browser
    and site/web-server.
  • SSL endorsement ensures that all correspondence
    that gets transmitted through a
    program/site/server is scrambled and decoded in
    such a way, that just the sender and the
    beneficiary would almost certainly observe it in
    the unscrambled structure.

4
How SSL Certificate Works?
  • The SSL Certificate-based encryption-unscrambling
    happens as a multi-step process and incorporates
    the accompanying advances
  • It starts with a program endeavoring to associate
    with a SSL-verified site.
  • The site requests that the web server distinguish
    itself.
  • At that point the site would react by recognizing
    itself with a duplicate of the SSL certificate
  • The following stage is the program checking in
    the event that it believes the SSL
    authentication. In the event that it does, a
    message is sent to the server.
  • At that point the server reacts with a carefully
    marked affirmation to begin a SSL encoded
    session.
  • The completely encoded correspondence between the
    client/program and the site/server begins from
    that point.

5
How SSL/HTTPS Sniffing Happens?
  • SSL sniffing works in various ways.
  • In some SSL executions, the MITM intermediary is
    utilized to divert the end client in a
    correspondence to a non-HTTPS site and afterward
    sniff the non-encoded traffic in that site.
  • In the meantime, solicitations would be
    handed-off to and from the HTTPS site by means of
    an intermediary.
  • The man in the center can on the other hand get
    the HTTPS traffic and present a legitimate HTTPS
    endorsement to the end client.
  • The endorsement would should be trusted on the
    end client machine.

6
How SSL/HTTPS Sniffing Happens? Continued
  • This the end client machine would should be
    undermined or a believed declaration must be
    acquired.
  • The man in the center would then hand-off traffic
    to the real HTTPS site and in the meantime take a
    gander at the decoded traffic, sitting amidst
    everything.
  • There is another choice too-snatching the
    scrambled traffic and recording it, with the
    expectation that in future, innovation would help
    decode the information.

7
Issues Found with SSL Sniffing
  • There are fundamental issues related with SSL
    sniffing. A portion of these incorporate
  • SSL sniffing happens to be substantially more
    across the board than individuals might suspect
    or speculate
  • Applications that perform SSL review at times
    have defects that could put clients at expanded
    hazard
  • Some SSL reviewing programming neglect to approve
    authentications of those frameworks that they
    interface with and this could result in customers
    not having the capacity to know whether they are
    associated with a genuine site or not.
  • In spite of the fact that SSL review programming
    issue cautioning on identifying blunders, some
    SSL assessment programming would send customer's
    demand to the server preceding sending a notice
    to the client.
  • The hazard required here is that the programmer
    would in any case have the capacity to see and
    even adjust touchy information.

8
  • Comodo SecureBox is the best answer for SSL
    sniffing. It helps ruin SSL sniffing endeavors by
    distinguishing vindictive SSL associations and
    advising when somebody attempts to catch messages
    or authentications.
  • This enemy of sniffing happens when some
    programmer attempts to get onto a server, sniff
    out SSL data and endeavors to reproduce the site
    (for phishing), to include noxious codes (for
    hacking), to take data and so forth.
  • Comodo SecureBox forestalls SSL sniffing by
    blocking and confirming authentications, which it
    does by utilizing Comodo's believed root
    testament list. Along these lines it adequately
    figures out how to counteract Man-in-the-Middle
    assaults.

9
Prevent from SSL Sniffing
  • Get The Best protection Against SSL Sniffing
  • using SecureBox https//securebox.comodo.com/ss
    l-sniffing/

10
Questions?
11
Thank You!!
Write a Comment
User Comments (0)
About PowerShow.com