A hacker group has released a proof-of-concept tool that exploits how encryption keys can be renegotiated to launch a distributed denial of service attack against Secure Sockets Layer servers.. A tool designed to launch denial of service attacks can bring down Secure Sockets Layer servers using just a laptop computer and a standard DSL connection. Developed by a German group called The Hacker's Choice, THC-SSL-DOS tool is intended to be a proof-of-concept to disclose "fishy security" in the SSL protocol, the group wrote on The Hacker's Choice blog Oct. 24. The link for this article located at eWeek is no longer available. . An innovative application exposes TLS weaknesses by executing DDoS strikes seamlessly on networks.. SSL Threat Tool, Denial of Service Attack, Encryption Exploit. . LinuxSecurity.com Team
Cryptologists have now developed even more sophisticated attacks on AES encryption systems. According to crypto expert Bruce Schneier, a team consisting of Alex Biryukov, Orr Dunkelman, Nathan Keller, Dmitry Khovratovich and Adi Shamir have managed to crack reduced versions of AES-256 in practical length of time. Attacking nine-round AES-256 required 239 time, which is even feasible with an ordinary PC, while ten-round would require 245. The time required for eleven rounds, however, is just above practicality at 270. The attack exploits a vulnerability in the key schedule, a function AES-256 uses to derive sub-keys from the main key.. While the new attacks represent major progress in the cryptanalysis of AES, they are still irrelevant for attacks against real-world AES implementations and this is not only because of the reduced number of rounds (by default, AES-256 uses 14 rounds). Also, the attack is a related-key attack, which means that the attacker must have access to the plaintext of several units of ciphertext encrypted with keys that are related in a specific way. Such scenarios can theoretically only be found, for example, in hard disk encryption and network protocols, where the individual block keys are generated in such a weak way. The link for this article located at H Security is no longer available. . New developments in RSA cryptanalysis reveal noteworthy vulnerabilities in secure communications; however, they fall short of practical implementation.. AES Attacks,Cryptographic Security,Data Protection Techniques,Key Management. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.