sslsplit - Transparent and scalable SSL/TLS interception

Property Value
Distribution NetBSD 7.2
Repository NetBSD i386
Package filename sslsplit-0.4.10nb1.tgz
Package name sslsplit
Package version 0.4.10nb1
Package release -
Package architecture i386
Package type tgz
Category security
License 2-clause-bsd
Maintainer -
Download size 48.57 KB
Installed size 139.83 KB
SSLsplit is a tool for man-in-the-middle attacks against SSL/TLS
encrypted network connections.  Connections are transparently
intercepted through a network address translation engine and
redirected to SSLsplit.  SSLsplit terminates SSL/TLS and initiates
a new SSL/TLS connection to the original destination address, while
logging all data transmitted.  SSLsplit is intended to be useful
for network forensics and penetration testing.
SSLsplit supports plain TCP, plain SSL, HTTP and HTTPS connections
over both IPv4 and IPv6.  For SSL and HTTPS connections, SSLsplit
generates and signs forged X509v3 certificates on-the-fly, based
on the original server certificate subject DN and subjectAltName
extension.  SSLsplit fully supports Server Name Indication (SNI)
and is able to work with RSA, DSA and ECDSA keys and DHE and ECDHE
cipher suites.  Depending on the version of OpenSSL, SSLsplit
supports SSL 3.0, TLS 1.0, TLS 1.1 and TLS 1.2, and optionally SSL
2.0 as well.  SSLsplit can also use existing certificates of which
the private key is available, instead of generating forged ones.
SSLsplit supports NULL-prefix CN certificates and can deny OCSP
requests in a generic way.  For HTTP and HTTPS connections, SSLsplit
removes response headers for HPKP in order to prevent public key
pinning, for HSTS to allow the user to accept untrusted certificates,
and Alternate Protocols to prevent switching to QUIC/SPDY.


Package Version Architecture Repository
sslsplit-0.4.10nb1.tgz 0.4.10nb1 amd64 NetBSD
sslsplit - - -


Type URL
Binary Package sslsplit-0.4.10nb1.tgz
Source Package sslsplit

Install Howto

Install sslsplit tgz package:

# pkg_add sslsplit

See Also

Package Description
sslwrap-206nb8.tgz Simple SSL wrapper
ssmping-0.9.tgz Ping for Any- and Single-Source Multicast
ssmtp-2.64nb3.tgz Extremely simple MTA to forward mail to a mail hub
ssss-0.5nb2.tgz Shamir's Secret Sharing Scheme
ssync-1.9.1.tgz Invoke rsync to distribute files to a set of hosts
st-1.9nb1.tgz Non-preemptive thread library for Internet applications
st-term-0.8.2.tgz Simple terminal implementation for X
stacks-2.2nb2.tgz Software pipeline for building loci from short-read sequences
stagit-0.9.2.tgz Static git page generator
stagit-gopher-0.9.2.tgz Static git page generator for gopher
stalonetray-0.8.3.tgz Stand-alone system tray
stan-math-2.18.1.tgz Stan Math library
standalone-tcsh-6.22.02.tgz Standalone version of the Extended C-shell
star-1.6.1nb3.tgz Unique standard tape archiver
starbug1-1.6.01nb18.tgz Light weight Bug Tracking System written in C and Perl