Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

SSL hack vulnerability details to emerge

Black Hat demo to show even extended validation certificates are vulnerable to man-in-the-middle attacks
By Tim Greene , Network World , 07/16/2009
  • Share/Email
  • Tweet This
  • Comment
  • Print

Confidential online connections like banking transactions made from public wireless hotspots remain vulnerable to attacks despite improved security that was supposed to fix the problem, researchers will demonstrate at the Black Hat security conference.

The vulnerability means that attackers can lurk in the middle of what victims think are secure SSL sessions with banks, retailers and other secure Web sites, picking off passwords and other information that can be used later to steal account funds or compromise confidential business data, say the researchers, Mike Zusman, a consultant with Intrepidus, and Alexander Sotirov, an independent researcher.

An improved method of qualifying businesses for SSL certificates – called extended validation (EV) SSL turns the address bar in browsers green to assure users that the connection is in fact being made using EV SSL certificates. It is supposed to indicate that end users are connecting with a legitimate business, not an attacker. To do so, the entity obtaining the SSL certificate has undergone prescribed scrutiny and qualified for the certificate.

More from Black Hat: How to use electrical outlets and cheap lasers to steal data

But a green bar may hide the fact that the browser is actually connecting using SSL certificates approved via the traditional, less secure version of certificate issuance called domain validation (DV), which has no guarantee that such validation criteria were met, Zusman says. Those DV connections can be compromised by attackers.

Fixing the vulnerability is complex and would require all Web sites to conform, so the best defense is to avoid using insecure public Wi-Fi networks, he says. “Use EVDO [broadband wireless service] or some other mobile broadband service that makes it more difficult to execute this type of attack,” he says. “Keep yourself out of situations where attackers can get at you.”
To take advantage of this weakness, hackers would set up laptops in a public Wi-Fi zone and use well known methods for compromising the wireless access points such as ARP or DNS spoofing or hacking management platforms.

With control of the DNS for the access point, the attackers can establish their machines as men-in-the-middle, monitoring what victims logged into the access point are up to. They can let victims connect to EV SSL sites – turning the address bars green. Subsequently, they can redirect the connection to a DV SSL sessions under a certificates they have gotten illicitly, but the browser will still show the green bar.

“The scary part is that from the victim’s side there’s really no sign that anything went wrong unless they look at the EV SSL session on the certificate that is served,” Zusman says, which is something most users don’t do.” After the fact they may see that someone accessed their account, but during the attack it’s very difficult to detect.”

Attackers could drop malware into victims’ browsers that would grab passwords later when they access sensitive sites from secure networks that the attackers have not cracked, he says.

  • Share/Email
  • Tweet This
  • Comment
  • Print

Comments (3)
Login
Forgot your account info?

are you sure?By Anonymous on July 16, 2009, 5:01 pmI commented here: http://securetheworld.blogspot.com/2009/07/is-ssl-broken.html I was reading Network World and for a very brief moment was alarmed to learn that...

Reply | Read entire comment

Bypass the poisoned DNS serversBy geoapps on July 17, 2009, 12:17 pmSince this attack relies on "... control of the DNS for the access point, the attackers can establish their machines as men-in-the-middle, ...", wouldn't hard-coding...

Reply | Read entire comment

much ado ... about?By ChloeB on July 17, 2009, 4:49 pm" a web server that serves only EV SSL-protected content should theoretically be immune from these types of attacks, he says." Nothing is wrong with EV SSL. "Extended...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed