Games | Software 
Search

Home|Channels|Hot news|Most visited|Highest rated|
Technology index
Hardware
Interviews
IT Companies
Security
Tech Weblogs
Technology
Set this page as your
home page
Add this page to your
favorites

Home Technology SlashDot IT

Man-In-the-Middle Vulnerability For SSL and TLS
November 5, 2009, 5:00 pm


imbaczek writes "The SSL 3.0+ and TLS 1.0+ protocols are vulnerable to a set of related attacks which allow a man-in-the-middle (MITM) operating at or below the TCP layer to inject a chosen plaintext prefix into the encrypted data stream, often without detection by either end of the connection. This is possible because an 'authentication gap' exists during the renegotiation process, at which the MitM may splice together disparate TLS connections in a completely standards-compliant way. This represents a serious security defect for many or all protocols which run on top of TLS, including HTTPS."

Read more of this story at Slashdot.


Read more...
E-mailE-mail  Printer friendlyPrinter friendly version


Rate this article: 1 2 3 4 5  

Related stories...
Tech Lobbyist Named to DHS Top Security Post
Zero-Day IE Exploit In the Wild
Top Five Causes of Data Compromise
Pipeline Worm Floods AIM With Botnet Drones
Hotel Minibar Key Opens Diebold Voting Machines
The Engine of US Jobs
Draft Scheme Standard R6RS Released
CryptoDox: Encyclopedia on Cryptography & Info
Analyzing 20,000 MySpace Passwords
Code Posted For New IE Exploit
Powered by Apache, PHP, MySQL © 2006 Elerion, ltd.