Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 72 guests and 3 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow Major blow to TLS 1.0
EH-Net
May 26, 2012, 07:05:56 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Major blow to TLS 1.0  (Read 5091 times)
0 Members and 1 Guest are viewing this topic.
cd1zz
Sr. Member
****
Offline Offline

Posts: 393


View Profile WWW
« on: September 20, 2011, 11:44:09 PM »

If you didn't see this, it's pretty interesting.

http://www.theregister.co.uk/2011/09/19/beast_exploits_paypal_ssl/

Logged

lorddicranius
Sr. Member
****
Offline Offline

Posts: 396



View Profile WWW
« Reply #1 on: September 21, 2011, 12:04:55 AM »

I didn't know about TLS 1.1/1.2 prior to reading that article.  My question: why isn't a newer version of the technology being used?  I guess I'm curious as to what the changes are in 1.1/1.2 compared to 1.0.  Were they just performance updates that people didn't think were worth using?  And since there wasn't any security issues, they didn't see a NEED to use the newer versions?
Logged

cd1zz
Sr. Member
****
Offline Offline

Posts: 393


View Profile WWW
« Reply #2 on: September 21, 2011, 08:47:52 AM »

Looks like a number of crypto advances in 1.1 and 1.2
http://en.wikipedia.org/wiki/Transport_Layer_Security#TLS_1.1_.28SSL_3.2.29

A few people in here try to shed some light on why its not supported in Chrome:
http://www.google.com/support/forum/p/Chrome/thread?tid=0539619c98f85cbb&hl=en

However, IIS 7.5 and >IE8 in Win 7 support TLS 1.2
« Last Edit: September 21, 2011, 09:23:18 AM by cd1zz » Logged

alucian
Full Member
***
Offline Offline

Posts: 190



View Profile
« Reply #3 on: September 21, 2011, 08:28:54 PM »

If this is true we are in a big s**t.

You can't convince the C*O of a bank (for example) that is better to upset a lot of customers than to put them at risk.

I wait to see what will happen Friday.
Logged

CISSP ISSAP, CISM/A, GWAPT, eCPPT, OSWP
tturner
Sr. Member
****
Offline Offline

Posts: 329


View Profile WWW
« Reply #4 on: September 27, 2011, 02:33:28 PM »

This story is somewhat FUD worthy as it requires an XSS vuln on the site in question. Lots of those out there to be sure and definitely a risk to address, but it's not a free pass to pwn any TLS 1.0 site.
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GSEC, OPSE, CSWAE, VCP

Next 6 months: GCIH, CSTP, STI MSISE
lorddicranius
Sr. Member
****
Offline Offline

Posts: 396



View Profile WWW
« Reply #5 on: September 30, 2011, 11:38:58 AM »

Looks like a number of crypto advances in 1.1 and 1.2
http://en.wikipedia.org/wiki/Transport_Layer_Security#TLS_1.1_.28SSL_3.2.29

A few people in here try to shed some light on why its not supported in Chrome:
http://www.google.com/support/forum/p/Chrome/thread?tid=0539619c98f85cbb&hl=en

However, IIS 7.5 and >IE8 in Win 7 support TLS 1.2

Thanks for those links, cd1zz.

For the curious (should be all of us, right? Tongue), a video demonstrating BEAST at work: http://www.youtube.com/watch?v=BTqAIDVUvrU
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.128 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.