Slashdot Mirror


SSL Renegotiation Attack Becomes Real

rastos1 and several other readers noted that the SSL vulnerability we discussed a couple of weeks back, which some researchers had claimed was too theoretical to worry about, has now been demonstrated by exploit. The attack description is available on securegoose.org. "A Turkish grad student has devised a serious, real-world attack on Twitter that targeted a recently discovered vulnerability in the SSL protocol. The exploit by Anil Kurmus is significant because it successfully targeted the so-called SSL renegotiation bug to steal Twitter login credentials that passed through encrypted data streams. All in all, a man in the middle is able to steal the credentials of a user authenticating himself through HTTPS to a trusted website."

2 of 97 comments (clear)

  1. Re:Kinda bad summary by Anonymous Coward · · Score: -1, Offtopic

    Understandably, I'm not too worried about [everything but Twitter] going down in flames any time soon.

    Did someone mention 'having a party'?

  2. Christmas gift.shoes,handbags,ugg boot,Tshirts, by coolforsale107 · · Score: -1, Offtopic

    http://www.coolforsale.com/ Best quality, Best reputation , Best services Our commitment, customer is God. Quality is our Dignity; Service is our Lift. Ladies and Gentlemen weicome to my coolforsale.com.Here,there are the most fashion products . Pass by but don't miss it.Select your favorite clothing! Welcome to come next time ! Thank you! Air jordan(1-24)shoes $33 Nike shox(R4,NZ,OZ,TL1,TL2,TL3) $35 Handbags(Coach lv fendi d&g) $35 Tshirts (Polo ,ed hardy,lacoste) $16 free shipping competitive price any size available accept the paypal Thanks