IETF Completes Vulnerability Fix For SSL Renegotiation Bug

Outsmart Malicious Hackers


You should remember the SSL Renegotiation bug from last year that was used to successfully attack twitter.

Finally IETF have come out with a fix for the issue, it’s natural it has taken some time as it’s a flaw in the actual protocol itself not in any specific implementation (which is usually the case).

The bug was fairly serious as demonstrated by the Twitter-jacking that took place exploiting the flaw. The bug basically allowed an attacker to conduct a man-in-the-middle attack and insert some malicious data at the beginning of a vulnerable SSL/TLS connection.

A fix that addresses a security vulnerability that could threaten SSL-protected Websites has been given the greenlight. The Internet Engineering Task Force (IETF) has finished work on a fix to a vulnerability in the Secure Sockets Layer protocol security researchers uncovered last August.

The vulnerability partially invalidates the SSL lock and allows attackers to compromise sites that use SSL for security—including banking sites and back-office systems that use Web services-based protocols. The issue was uncovered by Steve Dispensa and Marsh Ray, who work for two-factor authentication provider PhoneFactor.

“The bug allows a man-in-the-middle to insert some malicious data at the beginning of a vulnerable SSL/TLS connection, but does not allow him to directly read the data sent by the legitimate parties,” explained Ray. “This capability is referred to as a ‘blind plaintext injection attack.’ Initially, it was hoped that this limited capability would offer some mitigation. Unfortunately, it seems that HTTPS is particularly strongly affected because of its design, and an effective attack on the Twitter HTTPS API was demonstrated shortly after the vulnerability was publicly disclosed.”

Some of the open source providers of SSL implementations have fixed the bug in their software and released publicly available patches. These however are not officially merged with the main development trees as they were waiting for the official fix from the IETF.

It will take a while for all the major vendors to roll this into their software I guess, I’d hope to see everyone rolling out fixes by the end of January latest.

Who knows how many sites/apps are quietly being owned out there due to this bug.

A copy of the IETF draft can be found here. After incorporating feedback from the TLS community, the proposed fix was approved by the IESG on Jan. 7, 2010. The IESG is responsible for the technical management of IETF activities and the Internet standards process. The decision means customers can now begin to deliver patches that implement IETF’s change.

“Because of the large number and variety of systems affected, substantial interoperability testing [for the SSL extension] will be conducted by many vendors before they feel comfortable releasing a patch,” Ray said. “Some interoperability testing has already been done with preliminary versions of the patch, but another round of testing is occurring now that the details of the fix have been finalized by the IETF.

“Some of the open-source TLS implementations (OpenSSL, GnuTLS) have fixes in their publicly visible repositories, but have not released a formal patch as of right now,” he added. “Most of the larger vendors (open source and otherwise) have been given several months’ head start on implementing the fix, so they should not be starting from zero at this point.”

I’m glad to see something has been done about this issue and it has been treated seriously, imagine what would have happened if this was an issue with a Microsoft product?

They’d point fingers and create some FUD story claiming it wasn’t critical and only effected a small amount of systems under very specific circumstances.

Source: eWeek

Posted in: Exploits/Vulnerabilities, Secure Coding

, , , , , ,


Latest Posts:


StaCoAn - Mobile App Static Analysis Tool StaCoAn – Mobile App Static Analysis Tool
StaCoAn is a cross-platform tool which aids developers, bug bounty hunters and ethical hackers performing mobile app static analysis on the code of the application for both native Android and iOS applications.
snallygaster - Scan For Secret Files On HTTP Servers snallygaster – Scan For Secret Files On HTTP Servers
snallygaster is a Python-based tool that can help you to scan for secret files on HTTP servers, files that are accessible that shouldn't be public and can pose a s
Portspoof - Spoof All Ports Open & Emulate Valid Services Portspoof – Spoof All Ports Open & Emulate Valid Services
The primary goal of the Portspoof program is to enhance your system security through a set of new camouflage techniques which spoof all ports open and also emulate valid services on every port.
Cambridge Analytica Facebook Data Scandal Cambridge Analytica Facebook Data Scandal
One of the biggest stories of the year so far has been the scandal surrounding Cambridge Analytica that came out after a Channel 4 expose that demonstrated the depths they are willing to go to profile voters, manipulate elections and much more.
GetAltName - Discover Sub-Domains From SSL Certificates GetAltName – Discover Sub-Domains From SSL Certificates
GetAltName it's a little script to discover sub-domains that can extract Subject Alt Names for SSL Certificates directly from HTTPS websites which can provide you with DNS names or virtual servers.
Memcrashed - Memcached DDoS Exploit Tool Memcrashed – Memcached DDoS Exploit Tool
Memcrashed is a Memcached DDoS exploit tool written in Python that allows you to send forged UDP packets to a list of Memcached servers obtained from Shodan.


One Response to IETF Completes Vulnerability Fix For SSL Renegotiation Bug

  1. foobee January 19, 2010 at 5:26 pm #

    the piece was good until you got into the ms bashing