Slashdot Mirror


SSL Renegotiation Attack Becomes Real

rastos1 and several other readers noted that the SSL vulnerability we discussed a couple of weeks back, which some researchers had claimed was too theoretical to worry about, has now been demonstrated by exploit. The attack description is available on securegoose.org. "A Turkish grad student has devised a serious, real-world attack on Twitter that targeted a recently discovered vulnerability in the SSL protocol. The exploit by Anil Kurmus is significant because it successfully targeted the so-called SSL renegotiation bug to steal Twitter login credentials that passed through encrypted data streams. All in all, a man in the middle is able to steal the credentials of a user authenticating himself through HTTPS to a trusted website."

5 of 97 comments (clear)

  1. Well, I suppose thats another Benefit of Twitter.. by Monkeedude1212 · · Score: 5, Funny

    It's nice to have a Sandbox for testing the latest and greatest hacks and security protocols, where no one cares about the user and/or what information they've posted on the site.

  2. Kinda bad summary by Virak · · Score: 5, Insightful

    Important part of the article:

    He did it by injecting text that instructed Twitter's application protocol interface to dump the contents of the web request into a Twitter message after they had been decrypted.

    The only reason it was exploitable was because of Twitter's API. Understandably, I'm not too worried about the rest of the Internet going down in flames any time soon.

    1. Re:Kinda bad summary by teh_commodore · · Score: 5, Insightful

      Oh good. We're totally fine. It only works on sites that are poorly designed. And Twitter's been patched, so that leaves, well, I guess no one.

      --
      --"insert clever quote here"
  3. Good explanation of the bug by TLS spec author by cullenfluffyjennings · · Score: 5, Informative

    A good source of info about what this attack is and how serious it is can be found at
    http://www.educatedguesswork.org/2009/11/understanding_the_tls_renegoti.html

  4. Re:Not worried, fixed already by Anonymous Coward · · Score: 5, Insightful

    You are forgiven for the error. Anyone using a letter that could be mistaken for a number in any software version string should be cockpunched with brass knuckles coated in broken glass and lemon juice