BetaONE will rise again!


Reply
  #1  
Old 23rd Apr 06, 11:00 PM
NewsBot's Avatar
NewsBot NewsBot is offline
Senior Member
 
Join Date: Oct 2004
Posts: 30,903
NewsBot will become famous soon enough
SSL/TSL and SSH Not So Secure Anymore
Polish scientists from Wroclaw University of Technology have found a vulnerability in security technologies used across the Internet that may allow kleptographic attacks resulting in silent theft of information without user's awareness. The attack is only possible if client application has been modified by a malicious person e.g. by infecting computer system by a virus or persuading a user to install a plug-in, download or compile modified code. Such application would not send any additional information and would act according to protocol specification but the data sent over secure channel would easily be disclosed only by sniffing network traffic. Probably all of the SSL/TLS and SSH protocols may be affected including Internet Explorer, Outlook Express, Mozilla Firefox, Mozilla Thunderbird and Opera. The team led by prof. Miroslaw Kurylowski has already informed Internal Security Agency and is going to suggest software vendors to modify protocol's implementation to protect against cryptographic attacks. The change is relatively simple and requires changing only a few lines of code. View: Wroclaw University of TechnologyRead full story...



News source: Full Story
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump


All times are GMT +1. The time now is 12:35 PM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.