-
Posts
18801 -
Joined
-
Last visited
-
Days Won
745
Everything posted by Nytro
-
Salut, e mai mult o curiozitate, dar ar fi frumos sa vedem cam ca ce lucreaza lumea pe aici. Eu vreau sa vad cine lucreaza ca Developer/Security si cam care e procentul. Alegeti domeniul in care lucrati si daca vreti dati mai multe informatii, opinii si sugestii, intr-un post.
-
New design flaw found in crypto's TLS: Pretend to be a victim online Researchers reveal way to hoodwink encryption protocol – and how to fix it By John Leyden, 5 Mar 2014 Security researchers have developed a new man-in-the-middle attack against the cryptographic protocol TLS – a protocol that is used to encrypt online banking and shopping, and other sensitive connections, to thwart eavesdroppers. The so-called Triple Handshake attack can, in certain conditions, outwit vital checks carried out to verify the identity of a user connecting to a server over a secure connection. In other words, it's possible to for a malicious system to intercept a user's login credential (a client certificate in this case) and masquerade as that victim with any server that also accepts the same credential. The quirky flaw was uncovered by security researchers at the French National Institute for Research in Computer Science and Control (INRIA) and draws from their previous work in the field. The attack also has implications for the security of SSL (Secure Sockets Layer), the still widely used predecessor to TLS (Transport Layer Security), as the researchers explain on their website: We have discovered a new class of attacks against applications that rely on the TLS Internet Standard for securing their communications. Essentially, if a user connects to a malicious website and presents a TLS client certificate, the malicious website can then impersonate the user at any other website that accepts the same TLS client certificate. The attacks work with all TLS and SSL versions, as well as the DTLS variant. As you may have noticed, online websites and similar services typically use usernames and passwords rather than TLS client certificates to log users in. This limits the impact of the attack. In practice the flaw becomes more of a problem when it comes to logging into Wi-Fi access points. "Variants of our attacks apply to specific scenarios of standard authentication protocols that rely on TLS, such as the PEAP Wi?Fi authentication mechanism," the researchers explained, adding that their exploit is similar to a previously uncovered cryptographic flaw – the 2009 Ray and Rex TLS renegotiation attack. The researchers – Karthikeyan Bhargavan, Antoine Delignat-Lavaud, Cédric Fournet, Alfredo Pironti and Pierre-Yves Strub – advocate short?term application-level mitigations as well as long-term changes to the TLS protocol to strengthen the standard and safeguard its users against this latest attack and other assaults along the same lines. "Let me stress that the attacks we found exploit a protocol-level issue, and not specific implementation bugs," Pironti told El Reg. "We also propose short-term application-level mitigation, but we aim at getting the protocol fixed, which would solve the issue at its root." The French team have already notified major vendors of TLS software implementations (at Microsoft, Google and others) as well as the Internet Engineering Task Force (IETF) about their research. The experts publicly disclosed the attack and possible countermeasures at an IETF meeting in London on Tuesday evening. An outline of their research was posted ahead of this meeting on an IETF mailing list on Monday. A draft detailing proposed changes to strengthen the TLS protocol can be found here. 'People shouldn't panic' Infosec professionals and programmers' early reaction to the Triple Handshakes research was cautious. "In short, the TLS handshake hashes in too little information, and always has. Because of that it's possible to synchronise the state of two TLS sessions in a way that breaks assumptions made in the rest of the protocol," senior Google software engineer Adam Langley explained on his personal website. "I'd like to thank the researchers for doing a very good job of disclosing this. [They] even included a draft for fixing the TLS key derivation to include all the needed information to stop this attack. "People shouldn't panic. The impact of this attack is limited to sites that use TLS client-certificate authentication with renegotiation, and protocols that depend on channel binding. The vast majority of users have never used client certificates." Marsh Ray, an authentication expert at Microsoft, noted: "Criticality is difficult to gauge." Chris Eng, another security expert, half joked: "I'm just going to do what I usually do and wait for ?@tqbf? [Thomas H. Ptacek] to tell us if the SSL/TLS vuln(s) matter." Pironti and other researchers at INRIA previously discovered a way to exploit flaws in Google and Microsoft's web email services using a glitch in the TLS technology. ® Sursa: New design flaw found in crypto's TLS: Pretend to be a victim online • The Register
-
Din partea mea, daca zbori de aici, nu mai dai DDOS, si nu mai vad rspula aici, e ok, sunt de acord sa nu iti fie facute datele publice. Oricum nu e nevoie, totul se gaseste la simple cautari pe Google sau aici pe forum. PS: Nu stiu cine da DDOS site-ului tau, dar asa vezi si tu ca nu e frumos.
-
Din cate am inteles eu le-a CERUT el 300 de dolari, i-au dat banii, apoi i-a santajat ca daca nu ii dau 3000 de dolari ii fac datele publice. Ce contract bre? Oricum mi se rupe de cazul respectiv. Din partea mea datele trebuiau facute publice pentru ca a dat DDOS, atunci.
-
In mod normal nu sunt deloc de acord ca unui membru sa i se face datele publice pentru ShowOff, malware (non-banking) etc. dar cum baiatu' este cel care ne dadea DDOS... In plus, daca povestea cu 300 si 3000 de dolari este adevarata... Lipsa de etica. PS: Si-a postat in trecut niste date aici pe forum, public.
-
Muie, Steaua!
-
Acum merge. Nu sunt foarte detaliate, dar sunt ok. Materie de facultate, nu poti avea pretentii de la asa ceva. Thanks.
-
Nu stiu ce s-a intamplat, dar Gecko are dreptate pentru ca e moderator. RST's logic.
-
Sunteti prea activi aici. Topic inchis.
-
Cine mai comenteaza de-a-n-pulea are ban.
-
Va place sa comentati la toate cacaturile...
-
Sa imi ziceti daca mai patiti asta. Puneti un Wireshark daca se intampla si salvati pcap-ul.
-
Reţeaua informatică a MAI, protejată de hackeri printr-un nou program
Nytro replied to bubu2005's topic in Stiri securitate
Asa cum au bagat nu stiu cate milioane de euro intr-un portal de cacat, ma astept la asa ceva. Comunistii astia sunt chiar retardati. E spalare de bani, pe fata. -
Reţeaua informatică a MAI, protejată de hackeri printr-un nou program
Nytro replied to bubu2005's topic in Stiri securitate
"Valoarea total? a proiectului s-a ridicat la 17.881.980 de lei, dintre care 15.199.683 de lei au fost achita?i din Fondul Social European" Sa-i fut in inima. Sa ii futa cineva, sa le dea deface si sa faca toate datele publice. Sa-si bage programu' prin capu pulii si sa il scoata pe cur. Ce firma a realizat acel program? De catre cine e condusa? -
Uber kewl!
-
Nu va alegeti username-uri drept cuvinte cheie sau nume de functii (@mysql_connect de exemplu)
-
In sfarsit o informatie utila. Aveti AVG? Aveti Chrome? Toti? De pe Mozilla nu merge?
-
Ban. Nu va mai abateti de la subiect.
-
Babelor, veniti in cacat si cu niste detalii tehnice, inca nu mi-am reparat globul de cristal sa stiu de ce nu va merge. 1. La ping in gateway aveti raspuns? 2. DNS-ul e rezolvat corect? 3. Alte site-uri va merg (fara sa fie din cache)? 4. La ping raspunde RST? 5. La traceroute ajunge pana la server? 6. Se realizeaza conexiunea? 7. Se conecteaza pe portul 80? 8. Site-urile de "is this site down just for me" zic ca e down? 9. Cu un proxy va merge? 10. Cu Tor va merge? 11. De pe telefon (internet mobil) va merge? Completati formularul de mai sus macar.
-
Daca aveti probleme pe forum va recomand sa discutati cu em. El este cel mai de treaba si daca il rugati frumos si va tineti de capul lui o sa va ajute. Noi ii zicem "good guy em".
-
E "self" sau se poate executa si la altii?
-
Banuiesc ca te referi la "struct"-ul din C/C++. E simplu, sa luam un exemplu: 1. Un int, de obicei, se memoreaza pe 4 octeti 2. Un char se memoreaza intotdeauna pe 1 octet 3. Un float, de obicei, are 4 bytes Astfel, putem crea o structura compusa din mai multe campuri: struct Om // Sau typedef struct Om{ int varsta; float inaltime; }; O structura are avantajul de a grupa niste date care definesc un "obiect" (In C++ o structura chiar defineste un obiect, la fel ca si cuvantul "class"). In C doar se grupeaza niste date, in C++ insa "struct" este identif cu "class" cu exceptia faptului ca implicit in struct datele sunt "public" iar in class sunt "private". Nu te stresa cu aceste aspecte, le vei invata pe parcurs cand vei invata C++. Pentru inceput e de ajuns sa intelegi ca asa se pot grupa niste date. Astfel poti defini un obiect de tipul "Om", la fel cum definesti un "int". Om variabila_de_tipul_Om; // Sau 'struct Om variabila_de_tipul_Om;' int variabila_de_tipul_int; // Variabila simpla Cu variabila de tipul "Om" poti accesa datele astfel: variabila_de_tipul_Om.varsta = 12;variabila_de_tipul_Om.inaltime = 1.80; Si cam asta e tot. Daca datele sunt alocate dinamic, se schimba putin lucrurile: Om *variabila_de_tipul_Om_C = (Om *)malloc(sizeof(Om)); // Aloci, in C, spatiu pentru o structura de tipul OmOm *variabila_de_tipul_Om_CPP = new Om; // Aloci si apelezi contructorul (nu te intereseaza asta deocamdata) in C++ Iar pentru accesarea datelor: variabila_de_tipul_Om->varsta = 12;variabila_de_tipul_Om->inaltime = 1.80; Un lucru de care trebuie sa tii cont cand folosesti structuri e dimensiunea structurii: struct Test{ int x; // 4 bytes char y, z; // 2 bytes, cate unul fiecare } Desi in mod normal structura ar avea 6 bytes, de cele mai multe ori compilatorul "aliniaza memoria" la multipli de 4 octeti. Astfel este posibil ca dimensiunea structurii sa fie de fapt 8 octeti. De aceea e bine sa folosesti intotdeauna operatorul "sizeof" pentru a determina dimensiunea oricarui tip de date.
-
DEFCON 19: Bit-squatting: DNS Hijacking Without Exploitation (w speaker) Speaker: Artem Dinaburg Security Researcher, Raytheon We are generally accustomed to assuming that computer hardware will work as described, barring deliberate sabotage. This assumption is mistaken. Poor manufacturing, errant radiation, and heat can cause malfunction. Commonly, such malfunction DRAM chips manifest as flipped bits. Security researchers have known about the danger of such bit flips but these attacks have not been very practical. Thanks to ever-higher DRAM densities and the use of computing devices outdoors and in high-heat environments, that has changed. This presentation will show that far from being a theoretical nuisance, bit flips pose a real attack vector. First the presentation will describe bit-squatting, an attack akin to typo-squatting, where an attacker controls domains one bit away from a commonly queried domain (e.g. mic2osoft.com vs. microsoft.com). To verify the seriousness of the issue, I bit-squatted several popular domains, and logged all HTTP and DNS traffic. The results were shocking and surprising, ranging from misdirected DNS queries to requests for Windows updates. The presentation will show an analysis of 6 months of real DNS and HTTP traffic to bit-squatted domains. The traffic will be shown in terms of affected platform, domain queried, and HTTP resources requested. Using this data the presentation will also attempt to ascertain the cause of the bit-flip, such as corruption on the wire, in requestor RAM, or in the RAM of a third party. The presentation will conclude with potential mitigations of bit-squatting and other bit-flip attacks, including both hardware and software solutions. By the end I hope to convince the audience that bit-squatting, and other attacks enabled by bit-flip errors are practical and serious, and should be addressed by software and hardware vendors.