Submit a Story!
topics:

[TLS] MITM attack on delayed TLS-client auth through renegotiation
To : tls at ietf.org Subject : [TLS] MITM attack on delayed TLS-client auth through renegotiation From : Martin Rex Date : Wed, 4 Nov 2009 18:28:00 +0100 (MET) Delivered-to : tls at core3.amsl.com List-archive : List-help : List-id : "This is the mailing list for the Transport Layer Security ...
Authentication Gap in TLS Renegotiation
extendedsubset.com — The SSL 3.0+ and TLS 1.0+ protocols are vulnerable to a set of related attacks which allow a man-in-the-middle (MITM) operating at or below the TCP layer to inject a chosen plaintext prefix into the encrypted data stream, often without detection by ... (more) Authentication Gap in TLS Renegotiation
Thoughts on the TLS bug
tombom.co.uk — So our old friend SSL has been broken again. I’ve had a little more time to chew on this than most, and a few thoughts have occurred to me. Firstly, let’s talk about its implications for HTTP. Assuming all the conditions are right (and ... (more) Thoughts on the TLS bug
Understanding the TLS Renegotiation Attack
educatedguesswork.org — Marsh Ray has published a new attack on the TLS renegotiation logic. The high level impact of the attack is that an attacker can arrange to inject traffic into a legitimate client-server exchange such that the TLS server will accept it as if it came ... (more) Understanding the TLS Renegotiation Attack
Comments
Blog Reactions

A zero-day flaw in the TLS and SSL protocols, which are commonly used to encrypt web pages, has been made public.
Hackers Center — ... as a preliminary solution. Ray said in his blog that he expected to see announcements from the multi-vendor collaboration "shortly", including an internet draft proposal for the fix. At the September meeting, Ray and Dispensa were informed about research being done by the IETF TLS Channel Bindings working group, which was following a similar line of inquiry into the TLS protocol. On Wednesday, Martin Rex, a member of the IETF TLS Channel Bindings working group and researcher at SAP, published a man-in-the-middle TLS renegotiation flaw in Microsoft IIS. The flaw, which is ...

SSL and TLS Authentication Gap vulnerability discovered
Ivan Ristić — ... advice can help the bypass of the client certificate authentication, though. If you can, monitor all connections that make use of the renegotiation feature. That won't help you if renegotiation is an integral feature of your web site, but it may do if it is rarely used. Further information: Marsh Ray's blog post (Marsh discovered the problem a couple of months ago) contains a detailed description of the problems in the attachment. The post by Martin Rex to the TLS mailing list that prompted public disclosure. ...

Generic Attack on SSL, TLS Exposed
Security Watch — ... . Then the first public discussion came, coincidentally, from Martin Rex of SAP on the IETF's TLS mailing list. Rex identified it as a problem specific, as far as he knew, to Microsoft's IIS, but he was on to the problem. ...

Yet Another SSL/TLS Vulnerability Released
...Application Security... — ... do rely on client side certificates for two-factor authentication. These groups should take notice and start preparing to implement any fixes when they are available. According to the Register article, this issue has been known since September and key players have been working to develop a solution. A new proposal is expected to be submitted to IETF today. Here are the links so far. Anyone out there have any more info at this time? Register Article Martin Rex Related Security Research & Response -Michael Coates ...

A zero-day flaw in the TLS and SSL protocols, which are commonly used to encrypt web pages, has been made public.
Hackers Center Blogs — ... as a preliminary solution. Ray said in his blog that he expected to see announcements from the multi-vendor collaboration "shortly", including an internet draft proposal for the fix. At the September meeting, Ray and Dispensa were informed about research being done by the IETF TLS Channel Bindings working group, which was following a similar line of inquiry into the TLS protocol. On Wednesday, Martin Rex, a member of the IETF TLS Channel Bindings working group and researcher at SAP, published a man-in-the-middle TLS renegotiation flaw in Microsoft IIS. The flaw, which is ...

TLS negotiation flaw published
CGISecurity - Website and Application Security News — Steve Dispensa and Marsh Ray have published a paper describing a weakness in the TLS negotiation process. This is the same attack discussed on the IETF TLS list . From the whitepaper"Transport Layer Security (TLS, RFC 5246 and previous, including SSL v3 and previous) is subject to a number of serious man-in-the-middle (MITM) attacks related to renegotiation. In general, these problems allow an MITM to inject an arbitrary amount of chosen plaintext into the beginning of the application protocol stream, leading to a variety of abuse possibilities. In particular, practical attacks ...

Related: ietf.org tls attack
TLS negotiation flaw publishedSecurity Bloggers Network
Steve Dispensa and Marsh Ray have published a paper describing a weakness in the TLS negotiation process. This is the same attack discussed on the IETF TLS list. From the whitepaper “Transport Layer Security (TLS, RFC 5246 and previous, including SSL v3 and previous) is subject to a ...
Understanding the TLS Renegotiation AttackEducated Guesswork
Marsh Ray has published a new attack on the TLS renegotiation logic. The high level impact of the attack is that an attacker can arrange to inject traffic into a legitimate client-server exchange such that the TLS server will accept it as if it came from the client. This may allow the attacker ...