Overclock.net - Overclocking.net
     
 
Home Gallery Reviews Blogs Register Today's Posts Mark Forums Read Members List


Go Back   Overclock.net - Overclocking.net > Industry News > Software News

Reply
 
LinkBack Thread Tools
Old 05-15-08   #1 (permalink)
First Time Build
 
intel ati

Join Date: Dec 2007
Posts: 770

Rep: 49 wolf_08 is acknowledged by some
Unique Rep: 40
Trader Rating: 0
Default [ZDN] Debian and Ubuntu OpenSSL generates useless crypto keys

Quote:
For almost two years the OpenSSL library used by Linux distribution Debian has been generating useless cryptographic keys — although Debian has issued a patch, experts warn that systems may still be exposed.


On Tuesday, the Debian project admitted that security expert Luciano Bello had discovered that an update to Debian's OpenSSL package in 2006 weakened the system's Random Number Generator, making SSH and SSL encryption and authentication — used to secure communications for applications such as Internet banking — useless.

"Because this vulnerability affects the OpenSSL package, which is used for generating various keys including SSH keys, session keys for SSL/TLS connections, OpenVPN and DNSSec keys and others, the implications are quite significant," Nishad Herath, chief executive officer of security consultancy Novologica, told ZDNet.com.au.

The vulnerability primarily affects Debian and Debian-derived systems, such as Ubuntu, according to Metasploit founder, H. D. Moore. However non-Debian systems are also exposed, said Herath.

"Non-Debian systems are also made vulnerable if they were using key material generated on an affected Debian system. To make matters worse, all DSA keys used for signing and authentication purposes on an affected Debian system is also made vulnerable — the Debian official security advisory recommends that such keys be considered compromised," said Herath.

Metasploit's Moore, yesterday told IT Radio's Risky Business that patching won't fix the problem either.

"Patching the vulnerability does not remove the vulnerability — it just prevents it from happening from that point on," he said.

Gabriel Haythornthwaite, information security consultant for Castelain, told ZDNet.com.au this means: "An attacker, who is predicting what a key would have been at the time, can break into a session or can retrospectively gather information from the session."

Novologica's Herath said this is a "spectacular screw up" on the part of the maintainers of the Debian system.

"It is quite commonplace that package maintainers of certain Linux distributions modify the source code of a given package to suit the specificities of a particular distribution. However, these changes are often not submitted to the original developers of the package for scrutiny," he said.

The changes made to the Debian OpenSSL package ... is in my view a spectacular screw up that clearly demonstrates the dangers of this modification process, where changes are not reviewed by the original authors of the package let alone any third-party experts prior to being made available to the public."

The Debian project has published a detector for known weak key material, which also provides instructions for rolling over encryption keys.
http://www.zdnet.com.au/news/securit...9289012,00.htm

------>
__________________
System: Xero
CPU
Q6600
Motherboard
GA-EX38-DS4
Memory
2 * 1 DDR2 800 Kingston
Graphics Card
Gecube 3870 O/C edition
Hard Drive
1 Maxtor ATA 200gigs, 1 Samsung SATA-2 500gigs
Sound Card
Integrated sound
Power Supply
OCZ 600watts
Case
Icute with side window and 25cm side fan
OS
Vista Home Premium
Monitor
View Sonic 17"
wolf_08 is offline   Reply With Quote
Old 05-15-08   #2 (permalink)
Intel Overclocker
 
satcom's Avatar
 
intel nvidia

Join Date: Aug 2007
Posts: 217

Rep: 5 satcom Unknown
Unique Rep: 4
Trader Rating: 0
Default

How does that happen?
__________________
System: Dr. Nguyen Van Falk
CPU
Q6600 G0
Motherboard
Asus P5K (vdroop mod)
Memory
Mushkin EM PC2-6400 4GB
Graphics Card
BFG 512mb 8800GTS
Hard Drive
WD Caviar SE16 250GB, Seagate 7200.11 500GB
Sound Card
Creative Audigy SE
Power Supply
Corsair HX620
Case
Coolermaster Cosmos
CPU cooling
Xigmatek HDT-S1283
OS
Vista x64
Monitor
24" Westinghouse 1920x1200
satcom is offline   Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools



All times are GMT -4. The time now is 06:35 PM.


Overclock.net is a Carbon Neutral Site Creative Commons License Internet Security By ControlScan

Terms of Service / Forum Rules | Privacy Policy | Advertising | Become an Official Vendor
Copyright © 2008 Shogun Interactive Development. Most rights reserved.
Page generated in 0.89692 seconds with 9 queries