• Log In
  • Register
Mtaram's Daze
  • Home
  • About me
    • Friends
    • iLike
  • Abstract
    • Color
    • Intellect
    • Pain
    • Poems
    • Success
  • Computers
    • Applications
    • Computer Troubleshooting
    • hardware
    • Security
      • Information Security
    • windows
  • General
    • Environment
    • Events
    • Finance
    • FUN n TP
    • How Tos
    • News
    • Reviews
    • Sidebar Photoblog
    • Sports
    • Work
  • Hacking
    • My Hacks
  • Internet
    • Google
    • Search
  • Mobile
    • Android
    • Apps
  • Social NW
    • Blog
    • Facebook
    • Twitter
    • Wordpress
  • Technology
    • Arduino
    • Gadgets
    • Gaming
  • 3 in 1 Search!
  • About US
  • RSS
  • May 18, 2013
  • SMS Updates

PS3 used to crack ssl

‹‹‹ Previous Post Next Post ›››
January 4, 2009
By Utkarsh

A team of security researchers and academics has broken a core piece of internet technology. They made their work public at the 25th Chaos Communication Congress in Berlin today. The team was able to create a rogue certificate authority and use it to issue valid SSL certificates for any site they want. The user would have no indication that their HTTPS connection was being monitored/modified.

This attack is possible because of a flaw in MD5. MD5 is a hashing algorithm; each unique file has a unique hash. In 2004, a team of Chinese researchers demonstrated creating two different files that had the same MD5 hash. In 2007, another team showed theoretical attacks that took advantage of these collisions. The team focused on SSL certificates signed with MD5 for their exploit.

The first step was doing some broad scans to see what certificate authorities (CA) were issuing MD5 signed certs. They collected 30K certs from Firefox trusted CAs. 9K of them were MD5 signed. 97% of those came from RapidSSL.

Having selected their target, the team needed to generate their rogue certificate to transfer the signature to. They employed the processing power of 200 Playstation 3s to get the job done. For this task, it’s the equivalent of 8000 standard CPU cores or $20K of Amazon EC2 time. The task takes ~1-2 days to calculate. The tricky part was knowing the content of the certificate that would be issued by RapidSSL. They needed to predict two variables: the serial number and the timestamp. RapidSSL’s serial numbers were all sequential. From testing, they knew that RapidSSL would always sign six seconds after the order was acknowledged. Knowing these two facts they were able to generate a certificate in advance and then purchase the exact certificate they wanted. They’d purchase certificates to advance the serial number and then buy on the exact time they calculated.

The cert was issued to their particular domain, but since they controlled the content, they changed the flags to make themselves an intermediate certificate authority. That gave them authority to issue any certificate they wanted. All of these ‘valid’ certs were signed using SHA-1.

If you set your clock back to before August 2004, you can try out their live demo site. This time is just a security measure for the example and this would work identically with a certificate that hasn’t expired. There’s a project site and a much more detailed writeup than this.

To fix this vulnerability, all CAs are now using SHA-1 for signing and Microsoft and Firefox will be blacklisting the team’s rogue CA in their browser products.

source

Tags: PS3 used to crack ssl

‹‹‹ Previous Post: HAPPY NEW YEAR 2oo9 Next Post: New year bash NITI’10 ›››

You might also like

‘Extremely weak’ security in file hosting sites A research carried out by the Katholieke Universiteit Leuven in Belgium and France's Institute Eurecom...
Intel core series of processors demystified The new 2010 Intel® Core™ i7 processor, Intel® Core™ i5 processor, and Intel® Core™ i3 processor...
How strong is your password If you invited me to try and crack your password, you know the one that you use over and over for like...
Increase in attacks on Social Networking Sites According to the Microsoft Security Intelligence Report, volume 10, there is a steady increase in social...
Grab This Widget

Line Break

Author: Utkarsh (473 Articles)

Solution designer with Firstsource solutions. A post grad in Networks and IT Infrastructure. Technology enthusiast, blogger, webdesigner, Network security aspirant and in love with electronics and gadgets. This blog is an attempt to share what I find interesting... almost anything @Mtaram on twitter and Google+

Leave a Reply

Click here to cancel reply.

Opt out of 'Thank You' e-mails..




Blogroll

  • Aima's blog
  • Anant Srivastav
  • Chatter That Matters
  • Computer Tricks and Tips
  • Harsh Ajmera's Blog
  • Life is Beautiful!!
  • Open Source Innovation
  • POET'S NOOK
  • Tech by a Teen
  • The Cyber Nag
  • The IT Axis
  • Vandy's Blog
  • VinolXi


Copyright © 2013 Mtaram's Daze. All Rights Reserved.
332 ‘queries’