SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security

More holes found in Web's SSL security protocol

More holes found in Web's SSL security protocol

By:  Robert McMillan  On: 10 Aug 2009 For: IDG News Service (San Francisco Bureau) Creator

At Black Hat, researchers say these bugs could be used with null termination certificates to create undetectable man-in-the middle attacks. Find out about the new vulnerabilities found by Dan Kaminsky

Security researchers have found some serious flaws in software that uses the SSL (Secure Sockets Layer) encryption protocol used to secure communications on the Internet.

At the recent Black Hat conference in Las Vegas, researchers unveiled a number of attacks that could be used to compromise secure traffic travelling between Web sites and browsers.

This type of attack could let an attacker steal passwords, hijack an on-line banking session or even push out a Firefox browser update that contained malicious code, the researchers said.

More in Network World Conficker talk sanitized at Black Hat to protect investigation

The problems lie in the way that many browsers have implemented SSL, and also in the X.509 public key infrastructure system that is used to manage the digital certificates used by SSL to determine whether or not a Web site is trustworthy.

A security researcher calling himself Moxie Marlinspike showed a way of intercepting SSL traffic using what he calls a null-termination certificate. To make his attack work, Marlinspike must first get his software on a local area network. Once installed, it spots SSL traffic and presents his null-termination certificate in order to intercept communications between the client and the server. This type of man-in-the-middle attack is undetectable, he said.

Marlinspike's attack is remarkably similar to another common attack known as a SQL injection attack, which sends specially crafted data to the program in hopes of tricking it into doing something it shouldn't normally do. He found that if he created certificates for his own Internet domain that included null characters -- often represented with a "0 -- some programs would misinterpret the certificates.

That's because some programs stop reading text when they see a null character. So a certificate issued to www.paypal.com"0.thoughtcrime.org might be read as belonging to www.paypal.com.

The problem is widespread, Marlinspike said, affecting Internet Explorer, VPN (virtual private network) software, e-mail clients and instant messaging software, and Firefox version 3.

To make matters worse, researchers Dan Kaminsky and Len Sassaman reported that they had discovered that a large number of Web programs are dependant on certificates issued using an obsolete cryptographic technology called MD2, which has long been considered insecure. MD2 has not actually been cracked, but it could be broken within a matter of months by a determined attacker, Kaminsky said.


Sign up for our Newsletters












Print |  Views: 880   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




robert mcmillan Robert McMillan is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

What to do in response to the DNS bombshell
What to do in response to the DNS bombshellA Canadian analyst advises e-businesses to ‘hound’ their ISPs asking for proof they have taken safeguards against DNS vulnerabilities. What Dan Kaminsky told Black Hat attendees
Entrust claims its SSL is secure
entrust inc. has announced its secure sockets layer certificates are not affected by a security hole discovered last month at the chaos communication congress.on dec. 30, a team of european researchers demonstrated they were able to exploit a weakness in the md
Protect yourself from the Internet Explorer bug
avg technologies nv of amsterdam announced this week version 8.0 of its security software has blocked 5,000 hacking attempts by miscreants exploiting a bug in the data binding features of microsoft internet explorer.avg version 8.0 includes rea
blog comments powered by Disqus