Blog | G5 Cyber Security

33 percent of all HTTPS websites open to DROWN attack

Security experts presented the DROWN attack that exploits a new critical security vulnerability affecting the OpenSSL. The new attack, dubbed DROWN (stands for Decrypting RSA with Obsolete and Weakened eNcryption), allows attackers to access users sensitive data over secure HTTPS communications. The attack could be successfully carried out in a few hours and in some cases the attackers is able to decrypt traffic in just a few seconds. It has been estimated that more than 33 percent of all HTTPS servers is vulnerable to the attack, roughly 11.5 million servers worldwide.”]

Source: https://securityaffairs.co/wordpress/44945/hacking/drown-attack.html

Exit mobile version