<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>True Insight &#187; cyber attack</title>
	<atom:link href="http://www.truedigitalsecurity.com/blog/tag/cyber-attack/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.truedigitalsecurity.com/blog</link>
	<description>Information Security in Today&#039;s Digital Culture</description>
	<lastBuildDate>Mon, 06 Feb 2012 19:22:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>BEAST: It&#8217;s What&#8217;s for Dinner</title>
		<link>http://www.truedigitalsecurity.com/blog/2011/09/29/beast-its-whats-for-dinner/</link>
		<comments>http://www.truedigitalsecurity.com/blog/2011/09/29/beast-its-whats-for-dinner/#comments</comments>
		<pubDate>Thu, 29 Sep 2011 13:05:22 +0000</pubDate>
		<dc:creator>Brett Edgar</dc:creator>
				<category><![CDATA[privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[cyber attack]]></category>

		<guid isPermaLink="false">http://www.truedigitalsecurity.com/blog/?p=741</guid>
		<description><![CDATA[For the past week, BEAST has been the talk of the InfoSec community.  BEAST stands for &#8220;Browser Exploit Against SSL/TLS&#8221; and is a new way to execute an attack against CBC mode encryption algorithms.  The attack has been theorized for quite some time (2006 seems to be about the time it became known), but until &#8230; <a href="http://www.truedigitalsecurity.com/blog/2011/09/29/beast-its-whats-for-dinner/">Read more <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div id="tweetbutton741" class="tw_button" style=""><a href="http://twitter.com/share?url=http%3A%2F%2Fgoo.gl%2FQB0FF&amp;via=lairofthewalrus&amp;text=BEAST%3A%20It%26%238217%3Bs%20What%26%238217%3Bs%20for%20Dinner&amp;related=&amp;lang=en&amp;count=horizontal&amp;counturl=http%3A%2F%2Fwww.truedigitalsecurity.com%2Fblog%2F2011%2F09%2F29%2Fbeast-its-whats-for-dinner%2F" class="twitter-share-button"  style="width:55px;height:22px;background:transparent url('http://www.truedigitalsecurity.com/blog/wp-content/plugins/wp-tweet-button/tweetn.png') no-repeat  0 0;text-align:left;text-indent:-9999px;display:block;"></a></div><p>For the past week, <a title="RAR of the BEAST paper and Java application" href="http://www.insecure.cl/Beast-SSL.rar" target="_blank">BEAST</a> has been the <a title="The Register article on BEAST" href="http://www.theregister.co.uk/2011/09/27/beast_attacks_paypay/" target="_blank">talk</a> of the <a title="Internet Storm Center diary entry on BEAST" href="http://isc.sans.edu/diary.html?storyid=11635" target="_blank">InfoSec community</a>.  BEAST stands for &#8220;Browser Exploit Against SSL/TLS&#8221; and is a new way to execute an attack against CBC mode encryption algorithms.  The attack has been theorized for quite some time (2006 seems to be about the time it became known), but until BEAST, an attacker had no practical way to execute the attack, and even with BEAST, the attack against CBC is still difficult to execute.<span id="more-741"></span></p>
<p>To execute a BEAST attack you must be able to &#8220;man-in-the-middle&#8221; (MitM) the network connection between the user and the web server.  Simplified, that means the attacker must be able to make network traffic between a target user&#8217;s browser and the web servers that user is talking to flow through the attacker&#8217;s computer.</p>
<p>The truth is, if you can MitM connections, you are going to have an easier time executing social engineering attacks (poisoning DNS queries, for instance) than executing the BEAST attack, although a savvy user may notice the social engineering.  The other 90% of users are going to be blissfully unaware.</p>
<p>So why all the hubbub?  The answer to that question is there is no easy way to fix this vulnerability.  Google has added some functionality to its Chrome browser that should be make it much harder (to the point of improbable) to execute BEAST against a Chrome user, and Mozilla is also working on a fix for its browsers.  You can bet Microsoft is working on it, too, but there is no simple fix.  TLSv1.1 and later aren&#8217;t vulnerable to this attack, but even though those protocols have been around for half a decade now, they are sparsely deployed.  Of the major browser vendors, I believe Microsoft is the only one that even offers the option of enabling those protocols, and that&#8217;s only as of Internet Explorer 9.0.  Fat lot of good it does IE9 users though &#8211; almost no web server on the planet supports TLSv1.1 or higher.  Why?  Because almost none of the browsers support it.  Chicken, meet egg.</p>
<p>If you&#8217;re paranoid, consider not connecting to untrusted wireless networks. (If you&#8217;re that paranoid, you probably don&#8217;t connect to wireless networks anyway.) Those are the easiest types of network for an attacker to MitM your connection, though far from the only type that is at risk.</p>
<p>Personally, I&#8217;m not too worried about it (yet).  By the time this attack becomes widespread (if ever), I expect the remaining browser vendors will have released updates to make it much harder to execute.  Maybe this will finally spur the adoption of the newer TLS protocols, though, and give the PCI SSC something else to ban from the Internet&#8230;</p>
<div class="wp-about-author-containter-none" style="background-color:#edf0f7;"><div class="wp-about-author-pic"><img alt='Brett Edgar' src='http://www.truedigitalsecurity.com/blog/wp-content/uploads/2012/01/Kayna-Kelley_avatar.jpg' class='avatar avatar-100 photo' height='100' width='100' /></div><div class="wp-about-author-text"><h3><a href='http://www.truedigitalsecurity.com/blog/author/bredgar/' title='Brett Edgar'>Brett Edgar</a></h3><p>Brett is a Founder and the Director of Managed Security Services at TRUE.  He has been working in the system and network forensics field since graduating from the University of Tulsa with a B.S. Computer Science in 2003.  He speaks hexadecimal fluently and is TRUE's resident human Ethernet transceiver.  He holds CISSP, CSSLP, and CNSS 4011-4015 certificates, loves MLB and NCAA Football, and when he gets tired of hexadecimal, he goes home to hang out with his wife and kid.</p><p><a href='lairofthewalrus' title='Brett Edgaron Twitter'>Twitter</a> - <a href='http://www.truedigitalsecurity.com/blog/author/bredgar/' title='More posts by Brett Edgar'>More Posts</a> </p></div></div>]]></content:encoded>
			<wfw:commentRss>http://www.truedigitalsecurity.com/blog/2011/09/29/beast-its-whats-for-dinner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

