Devilzc0de Forum Follow @devilzc0de
  • Home
  • Hacking
  • Networking
  • Programming
  • O.S
  • Server
  • Tweets
  • Search
  • Member List
  • Calendar
Current time: 06-19-2013, 07:31 PM Hello There, Guest! (Login — Register)
Devilzc0de Forum › Information Technology › Hacking › Web Attack Report v
« Previous 1 ... 8 9 10 11 12 ... 19 Next »

HTTPS SSL encryption Vulnerable To Crypto Attack

Home General Computer Multimedia Business Lounge

Post Reply 
Tweet
Threaded Mode | Linear Mode
HTTPS SSL encryption Vulnerable To Crypto Attack
09-25-2011, 08:41 PM
Post: #1
chaer.newbie Offline
--------------------------
*****
Dewa
Posts: 5,350
Joined: Dec 2009
Reputation: 189
HTTPS SSL encryption Vulnerable To Crypto Attack
[Image: 410-0821125944-Quantum.jpg]



The secure sockets layer (SSL) and transport layer security (TLS) encryption protocol, used by millions of websites to secure Web communications via HTTPS, is vulnerable to being decrypted by attackers.

Researchers have discovered a serious weakness in virtually all websites protected by the secure sockets layer protocol that allows attackers to silently decrypt data that's passing between a webserver and an end-user browser.

Juliano Rizzo and Thai Duong say the vulnerability compromises TLS (Transport Layer Security) 1.0, the encryption mechanism that secures Web sites accessed using HTTPS (Secure Hypertext Transfer Protocol). TLS is the successor to SSL (Secure Sockets Layer) and is widely used at financial sites. Companies, including Google, Facebook, and Twitter, are urging the wider use of TLS on the Web.

The exploit – demonstrated with a tool called BEAST – targets a flaw that could leave transactions open to attack and is being taken seriously by online payments firms.“We have got a team of security people and it is always working on updates and upgrades and they are looking into this already,” a PayPal spokesperson told PC Pro. “The details are still to be revealed, but the security people are trying to get a headstart on making sure this is kept secure."

BEAST requires attackers to gain a man-in-the-middle position. Most of the time this means that they need to be on the same network as their targets so they can intercept browser requests.BEAST has two components. One contains code that must be loaded into the victim's web browser and the second one captures and decrypts HTTPS session cookies. The researchers claim that they can decrypt any secure session cookie in five minutes on average.

http://thehackernews.com/2011/09/https-s...le-to.html
Find all posts by this user
Quote this message in a reply
09-26-2011, 01:11 AM
Post: #2
ikbal Offline
./Devilz Officer
Posts: 74
Joined: Feb 2011
Reputation: 1
RE: HTTPS SSL encryption Vulnerable To Crypto Attack
nice om chaerr aku lom ngerti beginian
Find all posts by this user
Quote this message in a reply
« Next Oldest | Next Newest »
Post Reply 


Topic Tools
Topic Link :
BBCode :
HTML Code :
View a Printable Version Send Thread to a Friend Subscribe to this thread
Submit Google Submit Face book Submit to Digg Submit to Reddit Submit to Furl Submit to Del.icio.us Submit to Jeqq

Possibly Related Threads...
Thread: Author Replies: Views: Last Post
Bug XSS Attack chordfrenzy.com tebe4rt 18 287 03-14-2013 12:36 PM
Last Post: abuabu_hat10
  [Tutor] » Facebook Tweaking » DDoS attack Group Facebook DC™Rebels 15 950 01-04-2013 06:36 AM
Last Post: PSYCOPUNK
Thumbs Up Anonymous Attack Facebook 28 januari ? benarkah itu ? ahmadridwan 16 424 01-27-2012 01:59 PM
Last Post: balonimia
  Indonesia Vulnerable SQLi SaccaFrazi 24 744 01-17-2012 07:58 AM
Last Post: SaccaFrazi
  [Tutor] xss lkpp.go.id vulnerable by me badwolves1986 11 268 01-15-2012 09:55 PM
Last Post: badwolves1986
  on going worldwide scene : "prolonged dns attack scene" ev1lut10n 2 282 10-07-2011 01:40 PM
Last Post: mariachi

Users Browsing
1 Guest(s)

  • Contact Us
  • devilzc0de
  • Return to Top
  • Mobile Version
  • RSS Syndication
  • Help
Current time: 06-19-2013, 07:31 PM Powered By MyBB, © 2002-2013 MyBB Group. Theme created by Justin S. | Mixed By Chaer.Newbie | Fixed By Aditya

USING THIS SITE INDICATES THAT YOU HAVE READ AND ACCEPT OUR TERMS. IF YOU DO NOT ACCEPT THESE TERMS, YOU ARE NOT AUTHORIZED TO USE THIS SITE