<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>stopthehacker.com &#187; CSRF</title>
	<atom:link href="http://www.stopthehacker.com/tag/csrf/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.stopthehacker.com</link>
	<description>Jaal, LLC</description>
	<lastBuildDate>Tue, 07 Feb 2012 14:00:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>New SSL Issues = New SSL Attacks</title>
		<link>http://www.stopthehacker.com/2009/11/23/new-ssl-issues-new-ssl-attacks/</link>
		<comments>http://www.stopthehacker.com/2009/11/23/new-ssl-issues-new-ssl-attacks/#comments</comments>
		<pubDate>Mon, 23 Nov 2009 22:48:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CSRF]]></category>
		<category><![CDATA[https]]></category>
		<category><![CDATA[malicious websites]]></category>
		<category><![CDATA[man in the middle]]></category>
		<category><![CDATA[MITM]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[TLS]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=649</guid>
		<description><![CDATA[You might remember the article I wrote a couple of weeks back regarding the then recently found vulnerabilities of SSL 3.0 (TLS 1.0). Well, things just got real. New Security Issues come to light with SSL 3.0 At the time, some researchers even went so far as to say that the vulnerability was only theoretical! [...]]]></description>
			<content:encoded><![CDATA[<p>You might remember the article I wrote a couple of weeks back regarding the then recently found vulnerabilities of SSL 3.0 (TLS 1.0). Well, things just got <em>real</em>.</p>
<ul>
<li><a href="http://www.stopthehacker.com/2009/11/05/new-security-issues-come-to-light-with-ssl-3-0/">New Security Issues come to light with SSL 3.0</a></li>
</ul>
<p>At the time, some researchers even went so far as to say that the vulnerability was only theoretical! Too theoretical to even worry about. The attack is described in detail:</p>
<ul>
<li><a href="http://www.securegoose.org/2009/11/tls-renegotiation-vulnerability-cve.html">TLS renegotiation vulnerability (CVE-2009-3555)</a></li>
</ul>
<p>It appears that the popular micro-blogging site Twitter first fell victim to the attack. The Register has the full story:</p>
<ul>
<li><a href="http://www.theregister.co.uk/2009/11/14/ssl_renegotiation_bug_exploited/">Researcher busts into Twitter via SSL reneg hole</a></li>
</ul>
<p>Now that the attack is in the wild, where are the patches?<br />
<span id="more-649"></span><br />
At the time of publishing, here is where everyone is:</p>
<p><strong>Open SSL</strong></p>
<ul>
<li>Workaround – Removes Renegotiation (OpenSSL 0.9.8l): Limited Public Availability</li>
<li>Fix (OpenSSL 0.9.8m): Code Undergoing Initial Testing</li>
</ul>
<p><strong>Microsoft</strong></p>
<ul>
<li>IIS, SChannel, Internet Explorer: Interoperability Testing in Progress</li>
<li>IIS6 and 7: Not Vulnerable to Client-Initiated Renegotiation</li>
</ul>
<p><strong>Cisco</strong></p>
<ul>
<li>Vulnerable Products: Code Undergoing Initial Testing</li>
</ul>
<p><strong>F5</strong></p>
<ul>
<li>Workaround – Disables Renegotiation: Limited Public Availability</li>
<li>Fix: Code Undergoing Initial Testing</li>
</ul>
<p><strong>NSS (Mozilla/Firefox)</strong></p>
<ul>
<li>TLS protocol fix: Interoperability Testing in Progress</li>
</ul>
<p><strong>Sun</strong></p>
<ul>
<li>Vulnerable Products: Code Undergoing Initial Testing</li>
</ul>
<p><strong>GNU TLS</strong></p>
<ul>
<li>Fix: Code Undergoing Initial Testing</li>
<li>Most Applications Are Not Affected</li>
</ul>
<p><strong>RSA</strong></p>
<ul>
<li>Vulnerable Products: Interoperability Testing in Progress/Limited Public Availability</li>
</ul>
<p><strong>Opera</strong></p>
<ul>
<li>Fix: Code Undergoing Initial Testing</li>
</ul>
<p>For more information and updates:</p>
<ul>
<li><a href="http://www.phonefactor.com/sslgap/ssl-tls-authentication-patches">SSL/TLS Authentication Gap – Status of Patches</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2009/11/23/new-ssl-issues-new-ssl-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

