This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Attack/exploit tool released - SSL issues...

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

Attack/exploit tool released - SSL issues…
- https://threatpost.com/en_us/blogs/attack-t…os-issue-102411
October 24, 2011 - "A group of researchers has released a tool that they say implements a denial-of-service attack against SSL servers by triggering a huge number of SSL renegotiations, eventually consuming all of the server's resources and making it unavailable. The tool exploits a widely known issue with the way that SSL connections work… The tool, which the researchers released for both Windows and Unix, implements the attack by establishing a large number of SSL connections with a given server. They said that the attack can be mitigated by servers that have SSL acceleration hardware installed, which speeds up the processing of the SSL operation…"

- https://isc.sans.edu/diary.html?storyid=11893
Last Updated: 2011-10-26 - "… very much "in our face" when doing vulnerability assessments, when web server after web server comes back with a vulnerability named something like "SSL Renegotiation saturation"… This tool targets the problem of SSL Renegotiation. With very limited bandwidth, a single host can DOS almost any vulnerable web server. Even offload devices such as load balancers are vulnerable (though more attacking hosts are required). In their release notes, THC makes the excellent point that the SSL renegotiation feature has never been widely used, and arguably should be simply disabled on almost all webservers. Unfortunately, SSL Renegotiation is enabled by default on many servers, and we all know what happens with defaults - systems get installed with default settings, then NEVER get changed…"

The BEAST summary - TLS, CBC, Countermeasures…
- http://blog.zoller.lu/2011/09/beast-summar…ermeasures.html
September 26, 2011

- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2011-3389
Last revised: 10/26/2011 - "… allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack…"
- https://www.kb.cert.org/vuls/id/864643

- https://bugzilla.mozilla.org/show_bug.cgi?id=665814
Modified: 2011-10-24
___

Certificate revocations by time - plotted:
- https://www.eff.org/sites/default/files/ima…_type-small.png
October 25, 2011
> https://www.eff.org/deeplinks/2011/10/how-secure-https-today
___

- http://h-online.com/-1366564
25 October 2011 - "… Anyone downloading and running the tool should, however, be aware that its use against external systems may constitute a criminal offence and is likely to be traceable."

:ph34r: :blink: :ph34r: