Get a Pentest and security assessment of your IT network.

News

Abusing X.509 Digital Certificates for Covert Data Exchange

Researchers at Fidelis Cybersecurity have identified a new technique for covertly exchanging data using X.509 digital certificates. The method builds on previous research involving the abuse of text fields in digital certificates to move data across a network. It takes advantage of the way digital certificates are exchanged during the initial TLS handshake, or the mutual authentication process that happens when two systems attempt to establish or resume a secure session with each other. The approach could be used to bypass security systems that do not check certificate extensions for abnormal content.”]

Source: https://www.darkreading.com/attacks-breaches/abusing-x-509-digital-certificates-for-covert-data-exchange

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Thousands of Magento websites compromised to serve malware

News

Office 365 Secure Score: An Introduction