Since there are still SSL setups that use MD5 in their certs why not add functionality to generate such certs using this attack http://www.phreedom.org/research/rogue-ca/ (the ca files and certificates they provided expired so they realistically can't be used) to then provide to sslsniff for use in it's other attacks or for things like WPA-enterprise attacks.