Reply
Old 12-31-2008, 07:45 AM SSL hacked
Novice Talker

Posts: 9
Name: Tom Raef
Trades: 0
Researchers successfully exploited a known “bug” with the MD5 hash algorithm to create duplicate SSL certificates.

As you know, when you want to show your site visitors that their transaction is safe with you, you purchase an SSL certificate. That certificate is registered to your domain and proves you are who you say you are.So, no other site can “prove” they are you because there is only one valid SSL certificate for your domain and you own it.

With this latest breakthrough, phishers can create bogus websites and duplicate your SSL certificate. It’s like having the same DNA between 2 or more people.

The really interesting part of this announcement is that the researchers used over 200 Sony Playstations to crack the encryption. That’s right. Sony Playstations.

Reportedly, the Playstation 3’s cell processor is quite handy with cryptographic calculations and therefore was a natural for this experiment.

Keep in mind that this was not found “in the wild”. It was conducted by researchers in a lab, however, if they can produce it, I’m sure the cybercriminals won’t be far behind.

What can you do to protect yourself and more importantly your customers?

Be sure your SSL certificate was created with SHA-1 hashing rather than the MD5 hash found vulnerable in this situation. I have read that VeriSign has just now changed their cryptographic hashing from MD5 to SHA-1 but I’m not sure if that is only for new certificates issued from this point forward or if you’re able to update yours.

Some of the CA’s (Certificate Authorities) still using MD5 hashing include: RapidSSL, FreeSSL, TC TrustCenter AG, RSA Data Security, Thawte and Verisign.co.jp

I also want to point out that using this information is quite complicated and would not be easy to implement, but the fact remains that you can be proactive now and prevent your certificate from being used in a malicious way.
__________________
We Watch Your Website - you go do what you do best!
Free Security Report

Last edited by WeWatch; 12-31-2008 at 11:31 AM.. Reason: removed formatting
WeWatch is offline
Reply With Quote
View Public Profile
 
 
When You Register, These Ads Go Away!
Old 12-31-2008, 11:09 AM Re: SSL hacked
Decaf's Avatar
Ultra Talker

Posts: 490
Name: Adam
Trades: 0
Do you have a url to verify the source, and what hacker is gonna spend enough money for 200 ps3's?
__________________
Decaf is offline
Reply With Quote
View Public Profile Visit Decaf's homepage!
 
Old 12-31-2008, 11:29 AM Re: SSL hacked
Novice Talker

Posts: 9
Name: Tom Raef
Trades: 0
I apologize for not posting the source. That's bad on my part. Here it is:

http://www.win.tue.nl/hashclash/rogue-ca/

Hackers aren't going to use 200 PS3s, but what if they were able to accomplish the same thing with one of their botnets? It will be interesting to see if this remains in the lab or ever does make it to "the wild".

I just thought it was newsworthy and easily preventable by verifying the algorithm used for any sites that you control.
__________________
We Watch Your Website - you go do what you do best!
Free Security Report
WeWatch is offline
Reply With Quote
View Public Profile
 
Old 12-31-2008, 01:24 PM Re: SSL hacked
Decaf's Avatar
Ultra Talker

Posts: 490
Name: Adam
Trades: 0
so, i was testing out some stuff and i found that i could get a string "a.txt" to have the exact same hash as a blank file called "a.txt". I'm thinking that this is because the file is blank but I'm not for sure.

__________________
Decaf is offline
Reply With Quote
View Public Profile Visit Decaf's homepage!
 
Old 12-31-2008, 03:25 PM Re: SSL hacked
tripy's Avatar
Do not try this at home!

Posts: 3,176
Name: Thierry
Location: I'm the uber Spaminator !
Trades: 0
Quote:
and what hacker is gonna spend enough money for 200 ps3's?
Mind you, the most active organizations that are below 90% of the phishing attempts are related to different mafias.

Do you really think that kind of organization will be reluctant to invest in PS3?

http://www.theregister.co.uk/2008/04..._embraces_net/
__________________
Only a biker knows why a dog sticks his head out the window.
tripy is online now
Reply With Quote
View Public Profile Visit tripy's homepage!
 
Old 01-09-2009, 05:51 PM Re: SSL hacked
AD7863's Avatar
15 Year Old Tech Blogger

Posts: 427
Name: Artful Dodger
Location: England, UK
Trades: 0
Woah, imagine all the fake paypal websites lol.
AD7863 is offline
Reply With Quote
View Public Profile Visit AD7863's homepage!
 
Reply     « Reply to SSL hacked
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML

 



Page generated in 0.12807 seconds with 13 queries