Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 28 guests and 2 members online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow Major blow to TLS 1.0
EH-Net
May 25, 2013, 05:31:23 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Major blow to TLS 1.0  (Read 8058 times)
0 Members and 1 Guest are viewing this topic.
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« on: September 20, 2011, 11:44:09 PM »

If you didn't see this, it's pretty interesting.

http://www.theregister.co.uk/2011/09/19/beast_exploits_paypal_ssl/

Logged

lorddicranius
Sr. Member
****
Offline Offline

Posts: 447



View Profile WWW
« Reply #1 on: September 21, 2011, 12:04:55 AM »

I didn't know about TLS 1.1/1.2 prior to reading that article.  My question: why isn't a newer version of the technology being used?  I guess I'm curious as to what the changes are in 1.1/1.2 compared to 1.0.  Were they just performance updates that people didn't think were worth using?  And since there wasn't any security issues, they didn't see a NEED to use the newer versions?
Logged

GSEC, eCPPT, Sec+
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« Reply #2 on: September 21, 2011, 08:47:52 AM »

Looks like a number of crypto advances in 1.1 and 1.2
http://en.wikipedia.org/wiki/Transport_Layer_Security#TLS_1.1_.28SSL_3.2.29

A few people in here try to shed some light on why its not supported in Chrome:
http://www.google.com/support/forum/p/Chrome/thread?tid=0539619c98f85cbb&hl=en

However, IIS 7.5 and >IE8 in Win 7 support TLS 1.2
« Last Edit: September 21, 2011, 09:23:18 AM by cd1zz » Logged

alucian
Full Member
***
Offline Offline

Posts: 225



View Profile
« Reply #3 on: September 21, 2011, 08:28:54 PM »

If this is true we are in a big s**t.

You can't convince the C*O of a bank (for example) that is better to upset a lot of customers than to put them at risk.

I wait to see what will happen Friday.
Logged

CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #4 on: September 27, 2011, 02:33:28 PM »

This story is somewhat FUD worthy as it requires an XSS vuln on the site in question. Lots of those out there to be sure and definitely a risk to address, but it's not a free pass to pwn any TLS 1.0 site.
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
lorddicranius
Sr. Member
****
Offline Offline

Posts: 447



View Profile WWW
« Reply #5 on: September 30, 2011, 11:38:58 AM »

Looks like a number of crypto advances in 1.1 and 1.2
http://en.wikipedia.org/wiki/Transport_Layer_Security#TLS_1.1_.28SSL_3.2.29

A few people in here try to shed some light on why its not supported in Chrome:
http://www.google.com/support/forum/p/Chrome/thread?tid=0539619c98f85cbb&hl=en

However, IIS 7.5 and >IE8 in Win 7 support TLS 1.2

Thanks for those links, cd1zz.

For the curious (should be all of us, right? Tongue), a video demonstrating BEAST at work: http://www.youtube.com/watch?v=BTqAIDVUvrU
Logged

GSEC, eCPPT, Sec+
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 1.087 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.