Stealing Certificates with Apostille

1 · Rob Fuller · Aug. 26, 2018, 1:30 p.m.
At Def Con 26, @singe and @_cablethief gave a talk on enterprise wireless attacks. When it’s video is released you should check it out. During that talk, they quickly touched on a tool written by Rogan Dawes another @Sensepost-er’s tool called “Apostille”. It is esentially a certificate stealing (cloning? faking? doppelganger-ing?) tool. However, that over simplifies what it does. To be more accurate, Apostille generates a clone of the certificate chain, identical in as many details as possible,...