Jump to content



Red Alert: HTTPS has been hacked!


  • You cannot reply to this topic
2 replies to this topic

#1 nka

    Geek God

  • [QiT] Admins
  • PipPipPipPipPipPipPipPipPipPip
  • 12,054 posts
  • LocationQuebec, Canada

Posted 26 September 2011 - 05:23 PM

Quote


Red alert: HTTPS has been hacked

There's now a tool that exploits a flaw in SSL and TLS. Will the industry respond fast enough?

By Roger A. Grimes | InfoWorld

Only a handful of exploits per decade reveal a vulnerability that is truly significant. Thai Duong and Juliano Rizzo's BEAST (Browser Exploit Against SSL/TLS) attack will rank among them because it compromises the SSL and TLS browser connections hundreds of millions of people rely on every day.

BEAST cannot break the latest version of TLS -- the current standard based on SSL -- but most browsers and nearly all websites that support secure connections rely on earlier versions of the SSL and TLS protocols, which are vulnerable to BEAST attack. Browser vendors and websites that host secure connections are already scrambling to upgrade to TLS 1.1 or 1.2. How quickly that occurs depends on how many attacks occur in the wild.

The BEAST tool, presented last Friday at the 2011 Ekoparty Security Conference in Argentina, made real a theoretical SSL/TLS vulnerability first documented 10 years ago. It allows an attacker with previous MitM (man-the-middle) access to compromise a user's SSL/TLS-protected HTTPS cookie. This would allow an attacker to hijack the victim's active HTTPS-protected session or listen in on the previously cryptographically protected network stream. (Download Duong and Rizzo's paper on the BEAST attack [pdf].)
MitM attacks are fairly easy to do when the attacker and victim are located on the same local network (such as wireless networks, VPNs, or corporate LANs). Some hacking tools, such as Cain & Abel, make MitM attacks and network packet sniffing truly a click of a button.



Reste : http://www.infoworld...apup_2011-09-26

#2 nka

    Geek God

  • [QiT] Admins
  • PipPipPipPipPipPipPipPipPipPip
  • 12,054 posts
  • LocationQuebec, Canada

Posted 26 September 2011 - 05:36 PM

C'est pour dire que tout a une faille...! :)

#3 IAmLoco

    There's no place like ::1

  • [QiT] Gestionaires
  • PipPipPipPipPipPipPipPipPipPip
  • 6,115 posts
  • LocationQuebec , Quebec , Canada

Posted 26 September 2011 - 06:31 PM

Chrome a envoyer un fix pour cette vulnérabilité
http://www.theregist...atch_for_beast/
"Does an optimistic geek person look at a hard drive as half-full or half-empty?"
Google+ Profile
Google +1





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users