This forum is in archive mode. You will not be able to post new content.

Author Topic: HTTPS Hackable In 30 Seconds: DHS Alert  (Read 863 times)

0 Members and 1 Guest are viewing this topic.

Offline kenjoe41

  • Symphorophiliac Programmer
  • Administrator
  • Baron
  • *
  • Posts: 990
  • Cookies: 224
    • View Profile
HTTPS Hackable In 30 Seconds: DHS Alert
« on: August 13, 2013, 02:13:10 AM »
Department of Homeland Security urges all website operators to review whether they're vulnerable to new crypto attack. No easy fix exists.he so-called BREACH attack -- short for Browser Reconnaissance and Exfiltration via Adaptive Compression of Hypertext -- was detailed in a Department of Homeland Security (DHS) "BREACH vulnerability in compressed HTTPS" advisory, issued Friday, which warned that "a sophisticated attacker may be able to derive plaintext secrets from the ciphertext in an HTTPS stream." All versions of the transport layer security (TLS) and secure sockets layer (SSL) protocols are vulnerable.

http://www.informationweek.com/security/attacks/https-hackable-in-30-seconds-dhs-alert/240159435
If you can't explain it to a 6 year old, you don't understand it yourself.
http://upload.alpha.evilzone.org/index.php?page=img&img=GwkGGneGR7Pl222zVGmNTjerkhkYNGtBuiYXkpyNv4ScOAWQu0-Y8[<NgGw/hsq]>EvbQrOrousk[/img]

Offline vezzy

  • Royal Highness
  • ****
  • Posts: 771
  • Cookies: 172
    • View Profile
Re: HTTPS Hackable In 30 Seconds: DHS Alert
« Reply #1 on: August 13, 2013, 02:16:39 AM »
All of the SSL attacks thus far have relied on exploiting HTTP compression, to the best of my knowledge.

Haven't really researched BREACH that much, but it's nice to see some panicking.
Quote from: Dippy hippy
Just brushing though. I will be semi active mainly came to find a HQ botnet, like THOR or just any p2p botnet

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: HTTPS Hackable In 30 Seconds: DHS Alert
« Reply #2 on: August 13, 2013, 06:12:10 AM »
Nice, HTTPS has been relatively secure except for the few attacks that have been effective.
Is there any tool or so released ? want to try it.
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline kenjoe41

  • Symphorophiliac Programmer
  • Administrator
  • Baron
  • *
  • Posts: 990
  • Cookies: 224
    • View Profile
Re: HTTPS Hackable In 30 Seconds: DHS Alert
« Reply #3 on: August 13, 2013, 12:28:24 PM »
This vulnerability was disclosed at the recent blackhat conference and the researchers promised to release a tool soon that will enable companies test there networks. The say they built there exploit from  builds on the Compression Ratio Info-leak Made Easy (CRIME) exploit.

Quote
"It's a very powerful tool that -- if you know how to use it under certain conditions and you know who you're targeting -- you could potentially compromise the security of their channel without them being aware. The victim is not going to see any certificate errors," says Angelo Prado, lead product security engineer at Salesforce.com, who, together with Neal Harris, application security engineer at Square, will be presenting information in a session titled "SSL, Gone in 30 Seconds-A BREACH beyond CRIME." "The attack is going to rely on being able to piggyback on the victim's browser."
If you can't explain it to a 6 year old, you don't understand it yourself.
http://upload.alpha.evilzone.org/index.php?page=img&img=GwkGGneGR7Pl222zVGmNTjerkhkYNGtBuiYXkpyNv4ScOAWQu0-Y8[<NgGw/hsq]>EvbQrOrousk[/img]

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: HTTPS Hackable In 30 Seconds: DHS Alert
« Reply #4 on: August 13, 2013, 12:32:19 PM »
Thats kinda nice of them , are they obligated to do so? (I think they are)
CRIME I indeed followed as it was supposed to be  The next big exploit in https.... radiosilence.
Ill wait for them tool and play with it.
« Last Edit: August 13, 2013, 12:32:42 PM by proxx »
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline Mordred

  • Knight
  • **
  • Posts: 360
  • Cookies: 135
  • Nvllivs in Verba
    • View Profile
Re: HTTPS Hackable In 30 Seconds: DHS Alert
« Reply #5 on: August 13, 2013, 08:04:53 PM »
This is a bit worrisome to say the least. I always viewed SSL as being one of the truly masterfully-crafted security protocols out there.

As usual, don't take anything for granted I guess.

Thank you for the info kenjoe41, a cookie for you sir!
\x57\x68\x79\x20\x64\x69\x64\x20\x79\x6f\x75\x20\x65\x76\x65\x6e\x20\x66\x75\x63\x6b\x69\x6e\x67\x20\x73\x70\x65\x6e\x64\x20\x74\x68\x65\x20\x74\x69\x6d\x65\x20\x74\x6f\x20\x64\x65\x63\x6f\x64\x65\x20\x74\x68\x69\x73\x20\x6e\x69\x67\x67\x72\x3f\x20\x44\x61\x66\x75\x71\x20\x69\x73\x20\x77\x72\x6f\x6e\x67\x20\x77\x69\x74\x68\x20\x79\x6f\x75\x2e

Offline vezzy

  • Royal Highness
  • ****
  • Posts: 771
  • Cookies: 172
    • View Profile
Re: HTTPS Hackable In 30 Seconds: DHS Alert
« Reply #6 on: August 13, 2013, 08:29:18 PM »
This is a bit worrisome to say the least. I always viewed SSL as being one of the truly masterfully-crafted security protocols out there.

All of the SSL exploits thus far haven't really targeted the RC4 backbone, so much as side channels like info leakage, known-plaintext and size analysis to predict input.

I'm not really sure about just how well RC4 is implemented in SSL, but just look at how well it went with WEP.
Quote from: Dippy hippy
Just brushing though. I will be semi active mainly came to find a HQ botnet, like THOR or just any p2p botnet

 



Want to be here? Contact Ande, Factionwars or Kulverstukas on the forum or at IRC.