George Noseevich (@webpentest) 's Twitter Profile
George Noseevich

@webpentest

ID: 708774510

calendar_today21-07-2012 10:35:21

708 Tweet

757 Followers

102 Following

George Noseevich (@webpentest) 's Twitter Profile Photo

I now officially have a practical case where a DROP firewall rule helped me achieve my goal, and a REJECT rule instead would have prevented the attack from working. Funny )

George Noseevich (@webpentest) 's Twitter Profile Photo

After doing various tests I'm now reasonably sure that current experimental TLS1.3 implementation in Schannel lacks support for any kind of session resumption.If TLS1.3 is enabled, the client doesn't even advertise session_ticket support in ClientHello.

George Noseevich (@webpentest) 's Twitter Profile Photo

Part 2 of my schannel research is out: b.poc.fun/decrypting-sch…. It is much shorter and focuses mainly on session resumption. As always, feedback is very welcome, especially RE TLS1.3 resumption in schannel.

Xappy (@thexappy) 's Twitter Profile Photo

Thing I learned today: Decrypting arbitrary TLS sessions on Windows (for code utilizing schannel): b.poc.fun/decrypting-sch… Great explanation, and very easy to use code, by George Noseevich

Thing I learned today: Decrypting arbitrary TLS sessions 
 on Windows (for code utilizing schannel):
b.poc.fun/decrypting-sch…
Great explanation, and very easy to use code, by <a href="/webpentest/">George Noseevich</a>
George Noseevich (@webpentest) 's Twitter Profile Photo

Hey H2HC, on your CFP page you have 2 deadlines - Oct 1 for proposals and Oct 17 for slides. Does that mean that you expect both proposals and slides before you make the decision about acceptance? Or only those who've received an acceptance note need to submit slides?