Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  SSL data injection

  Aruba Advisory ID: AID-020810 TLS Protocol Session Renegotiation Security Vulnerability

  msgid:20091221130346.
GA23192@otis.
atalante.redteam-
pentesting.
de?to=bugtraq@securit
yfocus.
com&from=RedTeam%
20Pentesting%20Gm
bH&folder=\\
3APA3A\Bugtraq&
subject=TLS%20Ren
egotiation%20Vuln
erability:
%20Proof

  [ MDVSA-2009:337 ] proftpd

  TLS / SSLv3 vulnerability explained (New ways to leverage the vulnerability)

From:RedTeam Pentesting <release_(at)_redteam-pentesting.de>
Date:22.12.2009
Subject:TLS Renegotiation Vulnerability: Proof of Concept Code (Python)

Information about a vulnerability in the TLS protocol was published in the
beginning of November 2009. Attackers can take advantage of that vulnerability
to inject arbitrary prefixes into a network connection protected by TLS. This
can result in severe vulnerabilities, depending on the application layer
protocol used over TLS.

RedTeam Pentesting used the Python module "TLS Lite" to develop proof of concept
code that exploits this vulnerability. It is published at

http://www.redteam-pentesting.de/publications/tls-renegotiation

to raise awareness for the vulnerability and its potential impact. Furthermore,
it shall give interested persons the opportunity to analyse applications
employing TLS for further vulnerabilities.

--
RedTeam Pentesting GmbH                    Tel.: +49 241 963-1300
Dennewartstr. 25-27                        Fax : +49 241 963-1304
52068 Aachen                    http://www.redteam-pentesting.de/
Germany                         Registergericht: Aachen HRB 14004
Geschäftsführer: Patrick Hof, Jens Liebchen, Claus R. F. Overbeck

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server