SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security

Security pro says new SSL attack can hit many sites

Security pro says new SSL attack can hit many sites

By:  Robert McMillan  On: 20 Nov 2009 For: IDG News Service (San Francisco Bureau) Creator
 

Leviathan Security Group has developed generic attack code using the Authentication Gap bug, but launching an attack is very difficult and first requires a man-in-the-middle attack

A Seattle computer security consultant says he's developed a new way to exploit a recently disclosed bug in the SSL protocol, used to secure communications on the Internet. The attack, while difficult to execute, could give attackers a very powerful phishing attack.

Frank Heidt, CEO of Leviathan Security Group Inc., says his "generic" proof-of-concept code could be used to attack a variety of Web sites. While the attack is extremely difficult to pull off -- the hacker would first have to first pull off a man-in-the-middle attack, running code that compromises the victim's network -- it could have devastating consequences.

The attack exploits the SSL (Secure Sockets Layer) Authentication Gap bug, first disclosed on Nov. 5. One of the SSL bug's discoverers, Marsh Ray at PhoneFactor Inc., says he's seen a demonstration of Heidt's attack, and he's convinced it could work. "He did show it to me and it's the real deal," Ray said.

The SSL Authentication flaw gives the attacker a way to change data being sent to the SSL server, but there's still no way to read the information coming back. Heidt sends data that causes the SSL server to return a redirect message that then sends the Web browser to another page. He then uses that redirect message to move the victim to an insecure connection where the Web pages can be rewritten by Heidt's computer before they are sent to the victim.

"Frank has shown a way to leverage this blind plain text injection attack into a complete compromise of the connection between the browser and the secure site," Ray said.

A consortium of Internet companies has been working to fix the flaw since the PhoneFactor developers first uncovered it several months ago. Their work gained new urgency when the bug was inadvertently disclosed on a discussion list. Security experts have been debating the severity of this latest SSL flaw since it became public knowledge.

Last week, IBM Corp. researcher Anil Kurmus showed how the flaw could be used to trick browsers into sending Twitter messages that contained user passwords.

This latest attack shows that the flaw could be used to steal all sorts of sensitive information from secure Web sites, Heidt said.

To be vulnerable, sites need to do something called client renegotiation under SSL and also to have some element on their secure Web pages that could generate a particular 302 redirect message.

Many high-profile banking and e-commerce Web sites will not return this 302 redirect message in a way that can be exploited, but a "huge number" of sites could be attacked, Heidt said.

With so many Web sites at risk to the flaw, Heidt says he does not intend to release his code immediately.

From the victim's perspective, the only noticeable change during an attack is that the browser no longer looks as though it's connected to an SSL site. The attack is similar to the SSL Strip attack demonstrated by Moxie Marlinspike at the Black Hat security conference earlier this year.


Sign up for our Newsletters

 












Print |  Views: 2335   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




robert mcmillan Robert McMillan is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Recent Canadian IT Jobs




Related Content

Online attack hits US government Web sites
Online attack hits US government Web sitesThe powerful attack has knocked the FTC's Web site offline and caused many outages in South Korea...
Gumblar attacks on Google search results intensifies
Gumblar attacks on Google search results intensifies A Web attack that peppers Google search results with malicious links has infected more than 3,000 Web sites and continues to grow
Entrust claims its SSL is secure
entrust inc. has announced its secure sockets layer certificates are not affected by a security hole discovered last month at the chaos communication congress.on dec. 30, a team of european researchers demonstrated they were able to exploit a weakness in the md
blog comments powered by Disqus