Showing posts with label Freak Attack. Show all posts
Showing posts with label Freak Attack. Show all posts

Sunday, 15 March 2015

BlackBerry Devices Vulnerable FREAK Leak


BlackBerry users has warned that a large number of devices vulnerable by FREAK flaw in SSL / TLS is that early March was unveiled. Through the vulnerability, an attacker who is between a target and the Internet is in some cases the encryption of the encrypted connection to downgrade to a weak encryption to crack then that and to see the encrypted traffic.

According BlackBerry are different versions of the operating system, the BlackBerry Enterprise Server (BES), BlackBerry Messenger (BBM) and other software vulnerable. The manufacturer says that the investigation into the leak is still running, but there's already decided to publish the vulnerable systems and software. An update is not yet available, but BlackBerry says that an attacker would first have to place between the user and the Internet to carry out an attack.

Default settings, common configurations, and general "best practices" would also help to prevent a successful attack.Furthermore, the problem would be solved if users send data that already are encrypted before they are sent over SSL. For example, in the case of S / MIME or PGP. When the BlackBerry FREAK leak will patch is unknown. This week came Apple and Microsoft already with updates.

Wednesday, 11 March 2015

Microsoft Patches 45 Vulnerabilities, Including Stuxnet And FREAK


Microsoft has during Patch Tuesday of March 14 released updates, which together 45 vulnerabilities in Windows, Office, Exchange and Internet Explorer fix, including the Stuxnet leak from 2010 and the recently discovered FREAK leak. Especially re-patching the Stuxnet leak creates experts in amazement.Through the vulnerability knew the Stuxnet worm and the Fanny-espionage worm to spread.

Only connect a USB stick that made ​​the leak abuse was sufficient to infect Windows, even stood Autorun and Autoplay disabled. It was in fact a whole new way to attack Windows computers. In 2010, Microsoft came up with an update for the leak, but this patch showed the vulnerable code is not corrected, allowing Windows computers all the time were vulnerable, so warn researchers from HP.

There is also an update to the " FREAK-leak "in SSL / TLS appeared. Through the vulnerability, an attacker who is between a target and the Internet is in some cases the encryption of the encrypted connection to downgrade to a weak encryption to crack then that and to see the encrypted traffic.

Other vulnerabilities

In addition to the update for the Stuxnet leak four other updates are labeled as critical. Through these updates fix vulnerabilities that an attacker in the worst case can take over the entire system. It comes to vulnerabilities in Internet Explorer, the VBScript Scripting Engine in Windows, Adobe Font Driver and Office. In the case of one of the IE-leakage was the vulnerability already publicly known before the patch appeared. Through other vulnerabilities that Microsoft patched attackers could increase their rights to systems retrieve information, cause a denial of service and bypass security measures.Can update via Windows Update .

Friday, 6 March 2015

Microsoft Warns Of TLS / SSL Vulnerability In Windows


Not only Android and Apple users at risk revealed by this week " FREAK attack "on TLS / SSL, even Windows users are vulnerable, so let Microsoft know . Through the leak, an attacker who is between a target and the Internet is in some cases the encryption of the encrypted connection to downgrade to a weak encryption to crack then that and to see the encrypted traffic.

Initially it was claimed that Apple TLS / SSL clients such as Safari, and the standard Android browser were vulnerable.According to Microsoft, the problem is also present in all supported versions of Windows. In order to succeed, the attack is also requires that the server that the user a secure connection setup supports "RSA key exchange export ciphers". Research among 14 million websites shows that this at 36.7% is still the case. Several Internet companies, however, have indicated that export-grade encryption to phase out.

Or Microsoft comes up with an emergency patch for the problem is still unknown. The software giant says to investigate the problem and on that basis to decide whether an emergency patch appears that the update through the monthly patch cycle is distributed. Microsoft claims to have no information to suggest that Windows users have been attacked by the vulnerability. In anticipation of the update, Windows Users weak encryption itself off . However, this can ensure that Windows can not connect to systems that support only weak encryption.

Researchers develop Freakattack.com that are far more vulnerable browsers than assumed initially. On the website you will find a list of vulnerable clients. It comes to Internet Explorer, Chrome on Mac OS, Chrome on Android, Safari on Mac OS X, Safari on iOS, the default Android browser, Blackberry browser, Opera on Mac OS X and Opera on Linux. Chrome on Mac OS is now an update available. Updates for Safari should appear next week.