BEAST creators develop new SSL attack
Security researchers Juliano Rizzo and Thai Duong – who released details of an attack on SSL/TLS last year, along with a tool called BEAST – are preparing to present a new attack on SSL/TLS at the Ekoparty Security Conference in Argentina later this month, according to Threatpost. The new attack has been given the name CRIME by the researchers.
The CRIME attack is based on a weak spot in a special feature in TLS 1.0, but exactly which that feature is has not been revealed by the researchers. They will say that all versions of TLS/SSL – including TLS 1.2, on which the BEAST attack did not work – are vulnerable. The researchers say that once they have placed themselves in the middle of a given network, they can sniff the HTTPS traffic and launch the attack. Their chosen way to get that position is by running JavaScript code in the victim's browser, but the attack doesn't rely on JavaScript.