Southperry.net
Hackers break SSL encryption - Printable Version

+- Southperry.net (https://www.southperry.net)
+-- Forum: Social (https://www.southperry.net/forumdisplay.php?fid=14)
+--- Forum: Current Events (https://www.southperry.net/forumdisplay.php?fid=55)
+--- Thread: Hackers break SSL encryption (/showthread.php?tid=47153)



Hackers break SSL encryption - Nalek - 2011-09-20

Quote:Researchers have discovered a serious weakness in virtually all websites protected by the secure sockets layer protocol that allows attackers to silently decrypt data that's passing between a webserver and an end-user browser.

The vulnerability resides in versions 1.0 and earlier of TLS, or transport layer security, the successor to the secure sockets layer technology that serves as the internet's foundation of trust. Although versions 1.1 and 1.2 of TLS aren't susceptible, they remain almost entirely unsupported in browsers and websites alike, making encrypted transactions on PayPal, GMail, and just about every other website vulnerable to eavesdropping by hackers who are able to control the connection between the end user and the website he's visiting.

At the Ekoparty security conference in Buenos Aires later this week, researchers Thai Duong and Juliano Rizzo plan to demonstrate proof-of-concept code called BEAST, which is short for Browser Exploit Against SSL/TLS. The stealthy piece of JavaScript works with a network sniffer to decrypt encrypted cookies a targeted website uses to grant access to restricted user accounts. The exploit works even against sites that use HSTS, or HTTP Strict Transport Security, which prevents certain pages from loading unless they're protected by SSL.

The demo will decrypt an authentication cookie used to access a PayPal account, Duong said.
Like a cryptographic Trojan horse

The attack is the latest to expose serious fractures in the system that virtually all online entities use to protect data from being intercepted over insecure networks and to prove their website is authentic rather than an easily counterfeited impostor. Over the past few years, Moxie Marlinspike and other researchers have documented ways of obtaining digital certificates that trick the system into validating sites that can't be trusted.

Earlier this month, attackers obtained digital credentials for Google.com and at least a dozen other sites after breaching the security of disgraced certificate authority DigiNotar. The forgeries were then used to spy on people in Iran accessing protected GMail servers.

By contrast, Duong and Rizzo say they've figured out a way to defeat SSL by breaking the underlying encryption it uses to prevent sensitive data from being read by people eavesdropping on an address protected by the HTTPs prefix.

“BEAST is different than most published attacks against HTTPS,” Duong wrote in an email. “While other attacks focus on the authenticity property of SSL, BEAST attacks the confidentiality of the protocol. As far as we know, BEAST implements the first attack that actually decrypts HTTPS requests.”

Duong and Rizzo are the same researchers who last year released a point-and-click tool that exposes encrypted data and executes arbitrary code on websites that use a widely used development framework. The underlying “cryptographic padding oracle” exploited in that attack isn't an issue in their current research.

Instead, BEAST carries out what's known as a plaintext-recovery attack that exploits a vulnerability in TLS that has long been regarded as mainly a theoretical weakness. During the encryption process, the protocol scrambles block after block of data using the previous encrypted block. It has long been theorized that attackers can manipulate the process to make educated guesses about the contents of the plaintext blocks.

If the attacker's guess is correct, the block cipher will receive the same input for a new block as for an old block, producing an identical ciphertext.

At the moment, BEAST requires about two seconds to decrypt each byte of an encrypted cookie. That means authentication cookies of 1,000 to 2,000 characters long will still take a minimum of a half hour for their PayPal attack to work. Nonetheless, the technique poses a threat to millions of websites that use earlier versions of TLS, particularly in light of Duong and Rizzo's claim that this time can be drastically shortened.

In an email sent shortly after this article was published, Rizzo said refinements made over the past few days have reduced the time required to under 10 minutes.

“BEAST is like a cryptographic Trojan horse – an attacker slips a bit of JavaScript into your browser, and the JavaScript collaborates with a network sniffer to undermine your HTTPS connection,” Trevor Perrin, an independent security researcher, wrote in an email. “If the attack works as quickly and widely as they claim it's a legitimate threat.”

Article.


Hackers break SSL encryption - Raul - 2011-09-20

So this is basically what hackers were apparently using to get the encrypted passwords from the MS site?
GG scientists, always behind the times.


Hackers break SSL encryption - Devil - 2011-09-21

Hmmm there we have the Dutch shame of the year company Diginotar again...

Funny detail: Diginotar went bankrupt yesterday after the Dutch government telecom watchdog OPTA declared all Diginotar SSL certificates invalid.

Diginotar was hacked by an Iranian hacker (group?) who got root acces (lol) to this SSL certificate provider and provided falsified SSL certificates for themselves from Google, Youtube, Wordpress, Facebook, etc, etc.

But now it seems SSL itself is insecure? Or is this only the old SSL 1.0? Article isn't clear about that...


Hackers break SSL encryption - Born2BeMild - 2011-09-21

it uses Java? I suppose using NoScript and other similar add-ons would help in protection, right?


Hackers break SSL encryption - Eos - 2011-09-21

Raul Wrote:So this is basically what hackers were apparently using to get the encrypted passwords from the MS site?

Please do not leap to random conclusions. I've asked you this before. You have zero evidence and almost as little understanding. Making claims like this, even in question form, just spread confusion and panic.


Hackers break SSL encryption - FenixR - 2011-09-21

Raul Wrote:So this is basically what hackers were apparently using to get the encrypted passwords from the MS site?
GG scientists, always behind the times.

Not everything in this world is related to the Hacking in Ms for fucks sakes.

pomegranate like this reminds you of how insecure the internet is, like walking down a dark alley in the middle of the night :S.


Hackers break SSL encryption - Heidi - 2011-09-25

dante9898 Wrote:Not everything in this world is related to the Hacking in Ms for fucks sakes.

Great quote. Added to sig as lots of people don't seem to realise that.


Hackers break SSL encryption - Raul - 2011-09-25

dante9898 Wrote:Not everything in this world is related to the Hacking in Ms for pineapples sakes.

pomegranate like this reminds you of how insecure the internet is, like walking down a dark alley in the middle of the night :S.
YOU'RE JUST SAYING THAT BECAUSE YOU'RE A HACKER.
[COLOR="#FFFFFF"]loljk. but it does sound basically exactly
like what hackers were supposedly doing to the MS site.
Probably was created not for MS,
but was found to work on Nexon's games.[/COLOR]

EDIT:
Eos Wrote:Please do not leap to random conclusions. I've asked you this before. You have zero evidence and almost as little understanding. Making claims like this, even in question form, just spread confusion and panic.

I don't actually recall you having asked me that before, but I'll take your word for it.
And I did say "were", mind you.


Hackers break SSL encryption - xLeviathan - 2011-09-30

Raul Wrote:YOU'RE JUST SAYING THAT BECAUSE YOU'RE A HACKER.

Haha, oh, we're not past this wild witch hunt?

Protip: Many SPers use hacks. Heads up bro!


Hackers break SSL encryption - Heidi - 2011-09-30

Raul Wrote:loljk. but it does sound basically exactly
like what hackers were supposedly doing to the MS site.
Probably was created not for MS,
but was found to work on Nexon's games.

The usage of the word "probably" here is concerning. More like it definitely wasn't.

*points at sig*


Hackers break SSL encryption - Born2BeMild - 2011-10-01

does Nexon even use encryption? last I was on their website, I never noticed the https anywhere.


Hackers break SSL encryption - Eos - 2011-10-01

Born2BeMild Wrote:does Nexon even use encryption? last I was on their website, I never noticed the https anywhere.

<form id="gnt_form" action="https://www.nexon.net/api/v001/account/login" method="POST">


Hackers break SSL encryption - Born2BeMild - 2011-10-01

Eos Wrote:<form id="gnt_form" action="https://www.nexon.net/api/v001/account/login" method="POST">

you learn something new everyday.