Get a Pentest and security assessment of your IT network.

News

New TLS decryption attack affects one in three servers due to legacy SSLv2 support

Security researchers have discovered a new weakness that could allow attackers to spy on encrypted communications between users and one in three HTTPS servers. The problem exits because many HTTPS servers still support the old and insecure SSL (Secure Sockets Layer) version 2 protocol. The attack, dubbed DROWN (Decrypting RSA with Obsolete and Weakened eNcryption), has several prerequisites, but is quite practical. Attack is significantly easier to pull off against servers using a version of the OpenSSL library that’s vulnerable to two known flaws.”]

Source: https://www.csoonline.com/article/3039729/new-tls-decryption-attack-affects-one-in-three-servers-due-to-legacy-sslv2-support.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

BlackEnergy exploits recently fixed flaws in Siemens WinCC

News

Google Chrome will block code injection from third-party software within 14 months