Blog | G5 Cyber Security

Security Pro Says New SSL Attack Can Hit Many Sites

A security consultant says he’s developed a new way to exploit a recently disclosed bug in the SSL protocol. The attack exploits the SSL (Secure Sockets Layer) Authentication Gap bug, first disclosed on Nov. 5. Heidt sends data that causes the SSL server to return a redirect message that then sends the Web browser to another page. He then uses that redirect message to move the victim to an insecure connection. The only noticeable change during an attack is that the browser no longer looks as though it’s connected to an SSL site.”]

Source: https://www.csoonline.com/article/2124610/security-pro-says-new-ssl-attack-can-hit-many-sites.html

Exit mobile version