placement for flash
  • RSS Feed

  • Categories

  • Tags

  • Archive

  • Calendar
<<  July 2010  >>
MoTuWeThFrSaSu
2829301234
567891011
12131415161718
19202122232425
2627282930311
2345678

  • Articles by Author

  • Recent posts

  • Blogroll

12/27/2009 4:39:00 PM

Hacking TLS

by Avri Schneider

Researchers have uncovered a flaw in the Transport Layer Security (TLS) protocol, allowing attackers to inject arbitrary text into an encrypted session. In some cases, this attack enables an attacker to completely compromise the secured connection by either performing an arbitrary action on behalf of the user, or stealing their credentials for later use.

Organizations, Banks and governments count on TLS/SSL to securely authenticate their users, clients and citizens. A flaw such as this puts the whole world at risk. TLS/SSL being susceptible to a man-in-the-middle attack is serious business. It's whole point was enabling two parties to exchange messages without the ability of an intercepting third party to see and/or manipulate any of the traffic, as well as authenticating each message as originating from the claimed sender. There is currently no patch or hot-fix that will not potentially break existing configurations and nothing but upgrading the technology used by everyone today will protect governments, organizations and users from this attack.

 More information can be found here: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555

Currently rated 4.0 by 2 people

  • Currently 4/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

Tags: , , ,

Vulnerabilities | eCrime

Comments

5/5/2010

Pingback from computersecurityarticles.info

Hacking TLS | Computer Security Articles

computersecurityarticles.info

5/12/2010

Pingback from dataprotectioncenter.com

Hacking TLS | Data Protection and Recovery Center

dataprotectioncenter.com