Subscribe to the RSS feed in case you are interested in updates
In order to allow me to update in a more convenient manner, the latest updates will be added to the G-SEC blog only. Once the final revision of this blog post will be achieved I will update this blog with the latest one.
Updated 21:00 GMT+1 / 12.2009 - added a whitepaper trying to explain the vulnerability and it's implications to a broader audience
After some in-house tests, we can confirm that the vulnerability presented at http://www.extendedsubset.com/ indeed real and should pose a significant threat to most. The vulnerability has been discovered by "Marsh Ray".
We are currently looking into possible mitigations and will update this blog post regularly with more information regarding said vulnerability - if available.
Mikestoolbox.net - Test client implementation for TLS renegotiation extension
Patches
OpenSSL 0.9.81( Attention: OpenSSL removed the TLS/SSL renegotiation feature from this package - you need to test application before/after updating to this version ) (via ISC)
GnuTLS patch (implements a new TLS extension proposed in the IETF Draft) (via SID)
Apache patch (patches renogtiation prefix attacks at the application layer, still need openssl fixes for other attacks)
Impacts :
Currently known to exist
In general an attacker positioned in the middle of a connection may inject arbritary content into the beginning of an authenticated strea, it will be interesting to see what potential impact this vulnerability has within each of the applications / protocols supporting it. IMAPS, FTPSSL, POP3 etc
For web servers - Attackers (if in the middle) can inject data into a segment that is authenticated to the web server, the web server will merge those requests and process them. (GET requests are trivially exploitable, POST are not known to be)
Mitigations :
Monitor renegotiation requests
To mitigate possible attacks against web applications - use an IPS/IDS/Application firewall to catch recurrent HTTP request that are enclosed within each other
Weekly Update 301
-
First up, I'm *really *sorry about the audio quality on this one. It's the
exact same setup I used last week (and carefully tested first) but it's
obviou...
Friday Squid Blogging: Squid Cubes
-
Researchers thaw squid frozen into a cube and often make interesting
discoveries. (Okay, this is a weird story.)
As usual, you can also use this squid po...
Examples Of Encoding Reversing
-
I recently created 2 blog posts with corresponding videos for the reversing
of encodings. The first one is on the ISC diary: “Decoding Obfuscated
BASE64 St...
Meet the Administrators of the RSOCKS Proxy Botnet
-
Authorities in the United States, Germany, the Netherlands and the U.K.
last week said they dismantled the "RSOCKS" botnet, a collection of
millions of hac...
In defense of crypto(currency)
-
Last week a group of technologists, including Bruce Schneier, sent a letter
to Congress outlining their concerns around cryptocurrency and urging
Congress ...
SOC 2025: Operationalizing the SOC
-
Posted under: Research and Analysis
So far in this series, we’ve discussed the challenges of security operations,
making sense of security data, and refin...
Satori Updates
-
I've continued to update Satori little by little out there on github.
Both updating the underlying code and fingerprints. Always happy to have
new id...
Zeek in Action Videos
-
This is a quick note to point blog readers to my Zeek in Action YouTube
video series for the Zeek network security monitoring project.
Each video addre...
Ten years, how time flies.
-
Ten years, a decade, it’s a very long time, and yet passes in the blink of
an eye.
I joined Tenable ten years ago, and somehow they have not tired of me ...
The MELLODDY Project from a Privacy Point of View
-
In MELLODDY, several of the world’s largest pharmaceutical companies aim to
leverage each other’s data by jointly training a multi-task machine
learning mo...
The Future of the FTC: Part II
-
A previous blog post discussed FTC Chairwoman Slaughter’s first priority as
the newly designated chairwoman – the COVID-19 pandemic. The FTC’s second
prior...
2020-12-13 SUNBURST SolarWinds Backdoor samples
-
*Reference*
I am sure you all saw the news.
2020-12-13 Fireeye
Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise
Multiple Glo...
WeirdAAL update - get EC2 snapshots
-
I watched a good DEF CON video on abusing public AWS Snapshots
https://www.youtube.com/watch?v=-LGR63yCTts
I, of course, wanted to check this out. There a...
SSTIC 2018
-
Nous sommes en 2018. Fuites de données, attaques massives, failles
structurelles, le monde constate chaque jour un peu plus à quel point la
sécurité est ...
In Which You Get a Chance to Save Democracy
-
Let’s start with the end: you can do something to change the broken
political landscape in the United States, but you have to act quickly.
Here’s a link to...
En français svp?
-
Mir stelle fest, datt graff vereinfacht, zu Lëtzebuerg 100.000 Lëtzebuerger
schaffen, 100.000 net-Lëtzebuerger Residenten an 200.000 Frontalieren. Datt
ënn...
Rogue One Sequel already being filmed!
-
There’s some really interesting leaked photos and analysis by Charles
Goodman. “Leaked photos from the Rogue One sequel (Mainly Speculation –
Possible Spoi...
VulnHub Stapler 1 Solution 2
-
You can find Solution 1 here.
After spending a night on this, I finally managed to solve the 2nd way to
get limited shell on this box. Let's see how this ...
McAfee SiteList.xml password decryption
-
Recently, a very good friend of mine (@Sn0rkY) pointed me out the story of
a pentester who recovered the encrypted passwords from a McAfee
SiteList.xml fil...
Learning SDR
-
I recently launched Software Defined Radio with HackRF, an instructional
video series that I hope will make it easier than ever for people to learn
the bas...
USENIX Security Symposium Slides
-
We're very happy to present the paper
Revisiting SSL/TLS Implementations - New Bleichenbacher Side Channels and
Attacks
by Christopher Meyer, Juraj Somo...
New Insights into Email Spam Operations
-
Our group has been studying spamming botnets for a while, and our efforts
in developing mitigation techniques and taking down botnets have
contributed in d...
RSA Announces End of RSA Security Conference
-
Aims to bring clarity to cloudy marketing messages through exhibit hall
chotskies Bedford, MA., – April 1, 2014 – RSA, the security division of
EMC, today ...
Samsung Galaxy S5 could be cheaper than Galaxy S4
-
Good news for would-be Samsung Galaxy S5 customers - the main smartphone
may end up being more economical as opposed to Galaxy S4 was when it
established. ...
Why I _am_ Speaking At RSA 2014
-
There’s been quite a bit of drama with regards to whether or not to boycott
the RSA conference over a deal that the RSA security vendor had made with
the N...
Router backdoor reloaded...
-
S i vous avez aimé l'histoire de la backdoor D-Link, vous allez A-DO-RER
celle-ci. C'est encore sur /dev/ttyS0 que ça se passe, où on apprend que
les route...
One year after, end of Magnificent 7 project !
-
It has been a year already since the start of the Magnificient 7 program !
So what happened during this year ? We added some features to enhance your
analy...
Mobile Device Forensics - Course Update
-
It's been a few weeks since the last update, but things have been busy. The
Fall 2012 term is now in Week 5 (wow, the semester is flying by). We've
covered...
NWScript JIT engine: Wrap-up (for now)
-
Yesterday, I provided a brief performance overview of the MSIL JIT backend
versus my implementation of an interpretive VM for various workloads.
Today, I’l...