DaemonForums  

Go Back   DaemonForums > DaemonForums.org > News

News News regarding BSD and related.

Reply
 
Thread Tools Display Modes
  #1   (View Single Post)  
Old 3rd February 2016
J65nko J65nko is offline
Administrator
 
Join Date: May 2008
Location: Budel - the Netherlands
Posts: 4,131
Default Crypto flaw was so glaring it may be intentional eavesdropping backdoor

From http://arstechnica.com/security/2016...ping-backdoor/

Quote:
Network tool contained hard-coded prime number that wasn't prime after all.

An open source network utility used by administrators and security professionals contains a cryptographic weakness so severe that it may have been intentionally created to give attackers a surreptitious way to eavesdrop on protected communications, its developer warned Monday.

Socat is a more feature-rich variant of the once widely used Netcat networking service for fixing bugs in network applications and for finding and exploiting security vulnerabilities. One of its features allows data to be transmitted through an encrypted channel to prevent it from being intercepted by people monitoring the traffic. Amazingly, when using the Diffie-Hellman method to establish a cryptographic key, Socat used a non-prime parameter to negotiate the key, an omission that violates one of the most basic cryptographic principles.
__________________
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump
Reply With Quote
  #2   (View Single Post)  
Old 4th February 2016
kpa kpa is offline
Port Guard
 
Join Date: Jul 2015
Posts: 18
Default

I'm not familiar with the OpenSSL DH implementation but one would assume that such a system should check the provided prime numbers for primality at least with a crude and fast method, maybe this isn't the case?
Reply With Quote
  #3   (View Single Post)  
Old 26th February 2016
jjstorm jjstorm is offline
Package Pilot
 
Join Date: Nov 2014
Location: Buenos Aires, AR
Posts: 144
Default

So much for the advantage of "peer scrutiny" of open source software
Reply With Quote
Reply

Tags
socat


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Et tu, Fortinet? Hard-coded password raises new backdoor eavesdropping fears J65nko News 0 12th January 2016 10:19 PM
Security Critical crypto bug in OpenSSL opens two-thirds of the Web to eavesdropping comet--berkeley News 6 13th April 2014 03:54 AM
Security Critical crypto bug leaves Linux, hundreds of apps open to eavesdropping J65nko News 0 4th March 2014 10:59 PM
Apache developers scramble to fix proxy flaw J65nko News 0 25th November 2011 11:07 AM
Security Security Flaw in the VTE Library vermaden News 0 23rd November 2011 01:26 PM


All times are GMT. The time now is 09:13 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content copyright © 2007-2010, the authors
Daemon image copyright ©1988, Marshall Kirk McKusick