Educause Security Discussion mailing list archives
SSL vulnerability you may not have heard about yet -
From: Scott Koger <skoger () EMAIL WCU EDU>
Date: Thu, 5 Nov 2009 22:55:44 -0500
From Marsh Ray, Steve Dispensa
http://extendedsubset.com/ "Summary Transport Layer Security (TLS, RFC 5246 and previous, including SSL v3 and previous) is subject to a number of serious man-in-the-middle (MITM) attacks related to renegotiation. In general, these problems allow an MITM to inject an arbitrary amount of chosen plaintext into the beginning of the application protocol stream, leading to a variety of abuse possibilities. In particular, practical attacks against HTTPS client certificate authentication have been demonstrated against recent versions of both Microsoft IIS and Apache httpd on a variety of platforms and in conjunction with a variety of client applications. Cases not involving client certificates have been demonstrated as well. Although this research has focused on the implications specifically for HTTP as the application protocol, the research is ongoing and many of these attacks are expected to generalize well to other protocols layered on TLS." http://extendedsubset.com/Renegotiating_TLS.pdf http://extendedsubset.com/Renegotiating_TLS_pd.pdf http://extendedsubset.com/renegotiating_tls_20091104_pub.zip Also reported in Networkworld and sans.org handler's diary - http://isc.sans.org/diary.html?storyid=7534&rss M. Scott Koger, CISSP Security Analyst Information Technology Western Carolina University Cullowhee, NC 28723 Office 828.227.2489 Fax 828.227.7700
Current thread:
- SSL vulnerability you may not have heard about yet - Scott Koger (Nov 05)