| | | RssFeeds
 
Get Free Newsletter Search   Search Search
         

Follow Us:

 
 
NC Print 
January 2010
Editorial
HP Targets Premium Workstation Market with New Features
By Invitation

»The Analyst Angle

»ProductivIT

»Technology & Risks

Microsoft Dangles ROI Bait to Push Exchange 2010 Adoption
Business Intelligence Tracks Flu Cases in Upstate New York
Next-Gen BI Is Here

» Open Source BI Makes a Beginning

» BI: New Models Emerge

» Better Transparency Through BI

» Marrying Strategic Intelligence with Operational Intelligence

» Small and Medium Business(es) Intelligence

» Column-oriented Technology Conditions RDBMS for OLAP

Tulip Telecom Hopes to Ride High on New Wings of Fiber
Muralikrishna K
On the Record

»Tony Tsao

»Pascal Laik

»Tom Gillis

»Richard Clifton

»Justin Rattner

No, the Cloud Won’t Evaporate
Case Study

»The Power of a Simple SMS

»Web 2.0 Leads Collaboration Revolution at Mahindra Group

What CEOs Want From CIOs
Coke's RFID-Based Dispensers Redefine Business Intelligence
7 Cloud Computing Myths Busted
How Indian CIOs Stack Up
Is ‘free’ actually free?
In the News
 EDGE 2009

Read More About the Best IT Implementations in the Country

 
       Read more >> 

Archive
 

Serious SSL Vulnerability Found


A vulnerability in the most common data security protocol on the Internet could allow secure Web sessions to be hijacked

 By Thomas Claburn, InformationWeek, November 6, 2009, 1230 hrs

Two security researchers with PhoneFactor, a provider of phone-based two-factor authentication, recently said that they had discovered a serious flaw in the SSL protocol, which is used to protect sensitive data in online transactions.


 

SSL, short for Secure Sockets Layer, is used for online banking and for secure e-mail and database access, among other things.

 

This vulnerability was discovered in August and disclosed by PhoneFactor researchers Marsh Ray and Steve Dispensa to a consortium of major tech industry companies and standards groups in September. The vulnerability was slated for disclosure next year, to give affected vendors time to patch their software.

 

But an independent security researcher discovered the vulnerability on his own and posted it to an Internet Engineering Task Force mailing list on November 4th.

 

The vulnerability could allow an attack to conduct a man-in-the-middle attack, whereby an attacker could hijack an authenticated SSL session and execute commands. In theory, neither the Web server nor the Web browser would provide any indication that the session had been subverted.

 

"Because this is a protocol vulnerability, and not merely an implementation flaw, the impacts are far-reaching," said Steve Dispensa, CTO of PhoneFactor, in a statement. "All SSL libraries will need to be patched, and most client and server applications will, at a minimum, need to include new copies of SSL libraries in their products. Most users will eventually need to update any software that uses SSL."

 

Other SSL vulnerabilities have been identified recently. Over the summer, at the Black Hat security conference in Las Vegas, Mike Zusman, principal consultant at Intrepidus Group, and Alex Sotirov, an independent security researcher, disclosed a Web browser design flaw that allowed an attacker to conduct a man-in-the-middle attack against websites with Extended Validation (EV) SSL certificates.

 

Another security researcher, Moxie Marlinspike, demonstrated a separate SSL flaw at the Black Hat conference in Washington, in February.

Print this Page   E-mail this Page
RATE THIS ARTICLE
 Worse   Better 
Comment:*
First Name:*
Last Name:*
Company:
City:*
E-mail:*
Verification Code:*

Type the characters you see in the picture above.
 
  Reset

Comments >>

11/8/2009 12:39:00 PM
 
good news
 
 - peeyush kumar,hcl,noida
1

Disclaimer >>

 

 

 Global CIO

Global CIO: The Top 10 CIO Issues For 2010

For CIOs, 2010 will require new emphases on customers, revenue, external information, and a passion for rapid change           
           Read More >> 

 

 Editor's Blog

IT Can Accelerate Inclusion

        

Read more >>  

 

 CIO Profile

Satish Pendse Muralikrishna K

VP and Head, Computers & Communication Division, Infosys Technologies

 Read more >>  

 

 International News

Facebook Hit By Clickjacking Attack

Social network targeted by emerging brand of attack that's hard to kill

 Read more >>

 

        

 Work Smart

Archive your mail      


Read more >>  

 

ADVERTISEMENTS >>

 
Powered By: ssCMS 2.2.0.0