Barney's Blog

Blog archive

SLL Flaw Found

A hole in the Secure Sockets Layer (SSL) protocol could let a hacker commandeer your computer through rogue Web sites.

The flaw, found by two researchers, will be demonstrated this Friday at a security conference in South America. The researchers have proof-of-concept code called Browser Exploit Against SSL/TTS --known by the much cooler name BEAST --  that exploits the flaw.

Hackers could, once they figure out how it works, steal authentication tokens and then launch an array of attacks including phishing.

Some flaws are due to new software or upgrades. In this case, the flaw has been around since the very dawn of SSL time.

Posted by Doug Barney on 09/21/2011 at 1:18 PM


Featured

  • Malwarebytes Affirms Other APT Attack Methods Used Besides 'Solorigate'

    Security solutions company Malwarebytes affirmed on Monday that alternative methods besides tainted SolarWinds Orion software were used in the recent "Solorigate" advanced persistent threat (APT) attacks.

  • How To Fix the Hyper-V Read Only Disk Problem

    DOS might seem like a relic now, but sometimes it's the only way to fix a problem that Windows seems ill-equipped to deal with -- like this one.

  • Microsoft Warns IT Pros on Windows Netlogon Fix Coming Next Month

    Microsoft on Thursday issued a reminder to organizations to ensure that their systems are properly patched for a "Critical"-rated Windows Netlogon vulnerability before next month's "update Tuesday" patch distribution arrives.

  • Microsoft Nudging Skype for Business Users to Teams

    Microsoft on Thursday announced some perks and prods for Skype for Business unified communications users, with the aim of moving them to the Microsoft Teams collaboration service instead.

comments powered by Disqus