Skip to main content

BEAST creators develop new SSL attack

posted onSeptember 7, 2012
by l33tdawg

Security researchers Juliano Rizzo and Thai Duong – who released details of an attack on SSL/TLS last year, along with a tool called BEAST – are preparing to present a new attack on SSL/TLS at the Ekoparty Security Conference in Argentina later this month, according to Threatpost. The new attack has been given the name CRIME by the researchers.

The CRIME attack is based on a weak spot in a special feature in TLS 1.0, but exactly which that feature is has not been revealed by the researchers. They will say that all versions of TLS/SSL – including TLS 1.2, on which the BEAST attack did not work – are vulnerable. The researchers say that once they have placed themselves in the middle of a given network, they can sniff the HTTPS traffic and launch the attack. Their chosen way to get that position is by running JavaScript code in the victim's browser, but the attack doesn't rely on JavaScript.

Source

Tags

Encryption Software-Programming Security

You May Also Like

Recent News

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th