Rogue PayPal SSL Certificate Available in the Wild

A forged SSL certificate that could allow an attacker to trick users of IE, Safari or Chrome on Windows into thinking that a fake PayPal page is legitimate, has been publicly released. The cert exploits an yet-to-be-patched null byte poisoning vulnerability in Microsoft's CryptoAPI.[ADMA... [ read more >> ]

PayPal null-prefix certificate publicly released

Image comment: PayPal null-prefix certificate publicly released
Image credits: Mozilla

PayPal null-prefix certificate publicly released