Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

DROWN Attack - New Server SSL Encryption Vulnerability Announced, 1/3 of Internet Is At Risk
DROWN Attack Website ^ | March 1, 2016 | (Various researchers)

Posted on 03/02/2016 1:10:04 PM PST by dayglored

As described in this paper "DROWN: Breaking TLS using SSLv2" (PDF), it is possible to crack current TLS encryption using an old, obsolete, but nevertheless still deployed protocol, SSLv2.

This is a server-side issue -- it is not something clients (normal users) can do anything about. Folks browsing the web have to rely on the system admins at their favorite websites, mail portals, banks, shops, etc. to fix this.

It is estimated that a third of the public servers on the Internet are vulnerable to this attack.

You can test the servers in a given domain using this tool from the researchers.


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: drown; internet; ssl; vulnerability; windowspinglist
Navigation: use the links below to view more comments.
first 1-2021-28 next last

1 posted on 03/02/2016 1:10:04 PM PST by dayglored
[ Post Reply | Private Reply | View Replies]

To: Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; amigatec; AppyPappy; arnoldc1; ATOMIC_PUNK; ...
System admins -- FIX YOUR SERVERS! ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

2 posted on 03/02/2016 1:10:52 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
See also:

https://www.openssl.org/news/secadv/20160301.txt

3 posted on 03/02/2016 1:12:44 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 2 | View Replies]

To: ShadowAce; Swordmaker; ThunderSleeps

Ping for your lists.


4 posted on 03/02/2016 1:14:47 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Banks?

Oh great.


5 posted on 03/02/2016 1:16:59 PM PST by Talisker (One who commands, must obey.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

I need to send this to my security minded friends in IT.


6 posted on 03/02/2016 1:17:08 PM PST by the_individual2014
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored

So is Free Republic at risk or not?


7 posted on 03/02/2016 1:18:01 PM PST by Blue Highway
[ Post Reply | Private Reply | To 1 | View Replies]

To: Talisker

lov.gov (The Library of Congress)? Why am I not surprised?


8 posted on 03/02/2016 1:19:44 PM PST by rockrr (Everything is different now...)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Talisker
Banks?

My CU is on the list.

If they overlooked this one, make me wonder what other server hardening they overlooked.

9 posted on 03/02/2016 1:25:22 PM PST by EVO X
[ Post Reply | Private Reply | To 5 | View Replies]

To: EVO X

Bank of America has a lot of vulnerabilities showing up on that test website


10 posted on 03/02/2016 1:28:15 PM PST by Blue Highway
[ Post Reply | Private Reply | To 9 | View Replies]

To: dayglored

Bookmarking


11 posted on 03/02/2016 1:29:54 PM PST by WildHighlander57 ((WildHighlander57, returning after lurking since 2000)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Blue Highway
So is Free Republic at risk or not?

It appears FR's secure server is at risk. Or, at least, that's what the offered tool says... CA....

12 posted on 03/02/2016 1:31:54 PM PST by Chances Are (Seems I've found that silly grin again....)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Blue Highway

I suspect there might be some healthcare providers, too..


13 posted on 03/02/2016 1:33:01 PM PST by EVO X
[ Post Reply | Private Reply | To 10 | View Replies]

To: dayglored

Huh? SSLv2 (and indeed all cipher suites using SSL) have been deprecated for a long time.

PCI compliance and auditing required SSL be turned off for a long time now.


14 posted on 03/02/2016 1:37:56 PM PST by Gideon7
[ Post Reply | Private Reply | To 2 | View Replies]

To: Blue Highway

Found this...

Results for freerepublic.com
The following domain names are vulnerable to man-in-the-middle attacks. Attackers may be able to impersonate the server and steal or change data.
Update server software at all IP addresses shown, and ensure SSLv2 is disabled.
Vulnerable Domains: Vulnerable Because:
secure.freerepublic.com
www.secure.freerepublic.com
view certificate
209.157.64.202:443
is vulnerable to CVE-2016-0703


15 posted on 03/02/2016 1:37:59 PM PST by glasseye
[ Post Reply | Private Reply | To 7 | View Replies]

To: Chances Are

Vulnerable Domains:
secure.freerepublic.com
www.secure.freerepublic.com

View certificate:
https://censys.io/ipv4?q=0a88f0ade2749ef6e482c87e8542350548326f9282621f3e5f1d7411c229f03d

Vulnerable Because:
209.157.64.202:443
is vulnerable to CVE-2016-0703


16 posted on 03/02/2016 1:43:09 PM PST by Protect the Bill of Rights
[ Post Reply | Private Reply | To 12 | View Replies]

To: glasseye

GMTA-some faster than others. :)


17 posted on 03/02/2016 1:43:57 PM PST by Protect the Bill of Rights
[ Post Reply | Private Reply | To 15 | View Replies]

To: Gideon7

what is PCI compliance?


18 posted on 03/02/2016 1:44:33 PM PST by Kirkwood (Zombie Hunter)
[ Post Reply | Private Reply | To 14 | View Replies]

To: glasseye

The MIM attack is theoretical. I’m not aware of it being exploited by hackers (you have to be/hack an ISP itself first).

The fix is easy. Just turn off TLS 1.1 and use 1.2 or later.

PCI audits have requrired dropping TLS 1.1 since mid 2015 anyway.

The whole article is FUD. Looks self promotional for some guy’s website.


19 posted on 03/02/2016 1:48:44 PM PST by Gideon7
[ Post Reply | Private Reply | To 15 | View Replies]

To: Kirkwood

PCI = Payment Card Industry. If you accept credit cards you get audited and scanned monthly and get flagged if you don’t comply.

Because of that software vendors are generally careful to keep web software up to date (Apache, IIS, etc).


20 posted on 03/02/2016 1:50:51 PM PST by Gideon7
[ Post Reply | Private Reply | To 18 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-28 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson