Get a Pentest and security assessment of your IT network.

Cyber Security

Socat Weak Diffie-Hellman Prime Number

OpenSSL address implementation in Socat contains a hard-coded Diffie-Hellman 1024-bit prime number that was not prime. An attacker could listen and recover secrets from a key exchange that uses them. A post to a technical forum discovered that the non-prime prime was introduced more than a year ago. A developer named Zhiang Wang provided a patch with the new prime. It’s unknown how Wang chose the prime, but other commenters on the forum said checks in OpenSSL and other tools used to generate primes cannot be sure if the numbers are prime.

Source: https://threatpost.com/socat-warns-weak-prime-number-could-mean-its-backdoored/116104/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security