Presentation is loading. Please wait.

Presentation is loading. Please wait.

By Swapnesh Chaubal Rohit Bhat. BEAST : Browser Exploit Against SSL/TLS Julianno Rizzo and Thai Duong demonstrated this attack.

Similar presentations


Presentation on theme: "By Swapnesh Chaubal Rohit Bhat. BEAST : Browser Exploit Against SSL/TLS Julianno Rizzo and Thai Duong demonstrated this attack."— Presentation transcript:

1 By Swapnesh Chaubal Rohit Bhat

2 BEAST : Browser Exploit Against SSL/TLS Julianno Rizzo and Thai Duong demonstrated this attack.

3 SSL and TLS. Encryption of segments above the Transport Layer. Securing World Wide Web traffic carried by HTTP to form HTTPS

4

5 JavaScript code. Decrypt encrypted cookies. Vulnerability in websites protected by the secure sockets layer protocol. Silently decrypt the data.

6 TLS < 1.0 All websites protected by SSL.

7 BEAST is different than most published attacks against HTTPS. The exploit works even against sites that use HSTS, or HTTP Strict Transport Security, which prevents certain pages from loading unless they're protected by SSL. encrypted transactions on PayPal, GMail and just about every other website vulnerable to eavesdropping by hackers

8 Firefox itself not vulnerable. No TLS 1.0, no control over content of connections. Developer version of its Chrome browser

9 Large organizations rely on java VPN Web conferencing.

10 Decrypt an authentication cookie used to access a PayPal account. Trick the user into inserting plaintext characters

11 “Empty fragment" feature in OpenSSL. Insert a single empty TLS record before every record. Randomizes the IV of the actual records. Tor Browser requires OpenSSL 0.9.7 or later

12

13 http://www.theregister.co.uk/2011/09/19/beast_exploit s_paypal_ssl/ http://en.wikipedia.org/wiki/Transport_Layer_Securit y https://blog.torproject.org/blog/tor-and-beast-ssl- attack http://www.theregister.co.uk/2011/09/29/firefox_killin g_java/

14 THANK YOU!


Download ppt "By Swapnesh Chaubal Rohit Bhat. BEAST : Browser Exploit Against SSL/TLS Julianno Rizzo and Thai Duong demonstrated this attack."

Similar presentations


Ads by Google