domingo, 30 de agosto de 2020

TLS-Attacker V2.2 And The ROBOT Attack

We found out that many TLS implementations are still vulnerable to different variations of a 19-year old Bleichenbacher's attack. Since Hanno argued to have an attack name, we called it ROBOT: https://robotattack.org

Given the new attack variants, we released a new version of TLS-Attacker 2.2, which covers our vulnerabilities.

Bleichenbacher's attack from 1998

In 1998, Daniel Bleichenbacher discovered that the error messages given by SSL servers for errors in the PKCS #1 1.5 padding allow an adversary to execute an adaptive-chosen ciphertext attack. This attack also belongs to the category of padding oracle attacks. By performing the attack, the adversary exploits different responses returned by the server that decrypts the requests and validates the PKCS#1 1.5 padding. Given such a server, the attacker can use it as an oracle and decrypt ciphertexts.
We refer to one of our previous blog posts for more details.

OK, so what is new in our research?

In our research we performed scans of several well-known hosts and found out many of them are vulnerable to different forms of the attack. In the original paper, an oracle was constructed from a server that responded with different TLS alert messages. In 2014, further side-channels like timings were exploited. However, all the previous studies have considered mostly open source implementations. Only a few vulnerabilities have been found.

In our scans we could identify more than seven vulnerable products and open source software implementations, including F5, Radware, Cisco, Erlang, Bouncy Castle, or WolfSSL. We identified new side-channels triggered by incomplete protocol flows or TCP socket states.

For example, some F5 products would respond to a malformed ciphertext located in the ClientKeyExchange message with a TLS alert 40 (handshake failure) but allow connections to timeout if the decryption was successful. We could observe this behaviour only when sending incomplete TLS handshakes missing ChangeCipherSpec and Finished messages.
See our paper for more interesting results.

Release of TLS-Attacker 2.2

These new findings motivated us to implement the complete detection of Bleichenbacher attacks in our TLS-Attacker. Before our research, TLS-Attacker had implemented a basic Bleichenbacher attack evaluation with full TLS protocol flows. We extended this evaluation with shortened protocol flows with missing ChangeCipherSpec and Finished messages, and implemented an oracle detection based on TCP timeouts and duplicated TLS alerts. In addition, Robert (@ic0ns) added many fixes and merged features like replay attacks on 0-RTT in TLS 1.3.
You can find the newest version release here: https://github.com/RUB-NDS/TLS-Attacker/releases/tag/v2.2

TLS-Attacker allows you to automatically send differently formatted PKCS#1 encrypted messages and observe the server behavior:
$ java -jar Attacks.jar bleichenbacher -connect [host]:[port]
In case the server responds with different error messages, it is most likely vulnerable. The following example provides an example of a vulnerable server detection output:
14:12:42 [main] CONSOLE attacks.impl.Attacker - A server is considered vulnerable to this attack if it responds differently to the test vectors.
14:12:42 [main] CONSOLE attacks.impl.Attacker - A server is considered secure if it always responds the same way.
14:12:49 [main] CONSOLE attacks.impl.Attacker - Found a difference in responses in the Complete TLS protocol flow with CCS and Finished messages.
14:12:49 [main] CONSOLE attacks.impl.Attacker - The server seems to respond with different record contents.
14:12:49 [main] INFO attacks.Main - Vulnerable:true
In this case TLS-Attacker identified that sending different PKCS#1 messages results in different server responses (the record contents are different).
Related news
  1. Hack Rom Tools
  2. Hacking Tools For Games
  3. How To Make Hacking Tools
  4. Hacker Tools For Mac
  5. Pentest Tools Github
  6. Termux Hacking Tools 2019
  7. What Is Hacking Tools
  8. Hacking Tools For Kali Linux
  9. Hacking Tools For Kali Linux
  10. Pentest Tools For Android
  11. Hacker Search Tools
  12. Hacker Tools 2020
  13. Hacking Tools Kit
  14. Nsa Hacker Tools
  15. Hack Tools For Windows
  16. Install Pentest Tools Ubuntu
  17. Hacker Tools Free
  18. New Hack Tools
  19. Hacker Tools For Ios
  20. Hacker Tools Mac
  21. Hacking Tools For Windows Free Download
  22. Hacking Tools
  23. Android Hack Tools Github
  24. Hacker Tools Free Download
  25. Hacker Hardware Tools
  26. Hacker Tools For Mac
  27. Pentest Tools Framework
  28. Hack Tools Github
  29. Pentest Tools Review
  30. Free Pentest Tools For Windows
  31. Hacker Tools
  32. Hacker Security Tools
  33. Tools For Hacker
  34. Hacker Tools For Pc
  35. Hacking Tools Kit
  36. Pentest Box Tools Download
  37. Growth Hacker Tools
  38. Hacker Tools Hardware
  39. Hacker Tools Free Download
  40. Hacker Tools Free Download
  41. What Are Hacking Tools
  42. Hack Website Online Tool
  43. Hak5 Tools
  44. Hacking Tools Online
  45. Hacker Hardware Tools
  46. Pentest Box Tools Download
  47. Hacking Tools For Windows 7
  48. Hack Tools
  49. How To Hack
  50. Easy Hack Tools
  51. Hack Tools 2019
  52. Pentest Box Tools Download
  53. Pentest Tools Website
  54. Hacker Tools 2020
  55. Pentest Tools
  56. Hacking Tools Pc
  57. Hacking Tools 2019
  58. Hack Tools
  59. Hacking Tools For Games
  60. Hacking Tools For Kali Linux
  61. Hack Tools
  62. Hacker Tools 2019
  63. Hacking Tools For Mac
  64. Hacking Tools For Beginners
  65. Hack Tools Online
  66. Pentest Tools For Mac
  67. Usb Pentest Tools
  68. Pentest Tools Website
  69. Hacking Tools For Windows 7
  70. Best Hacking Tools 2019
  71. Hacking Tools
  72. Hacker Tools Hardware
  73. Hack Tools For Ubuntu
  74. Pentest Tools For Android
  75. Pentest Tools Website
  76. How To Install Pentest Tools In Ubuntu
  77. Hacker Tools Github
  78. Black Hat Hacker Tools
  79. Hacker Tools Apk
  80. Hacker Tools For Ios
  81. Hacker Tools Software
  82. Hacking Tools And Software
  83. World No 1 Hacker Software
  84. Bluetooth Hacking Tools Kali
  85. Hacker Tools For Pc
  86. Wifi Hacker Tools For Windows
  87. Hacker Tools For Ios
  88. Pentest Recon Tools
  89. Hacking Tools Software
  90. Pentest Tools Download
  91. Github Hacking Tools
  92. Pentest Tools Port Scanner
  93. Ethical Hacker Tools
  94. Pentest Tools Online
  95. Hack Tools For Mac
  96. Hacking Tools Name
  97. Hacker Tools List
  98. Hacking Tools Github
  99. Hacking Tools For Beginners
  100. Hacking Tools 2019
  101. Hack Tools Mac
  102. Hacker Tools 2020
  103. Pentest Tools Review
  104. Hack Tools For Mac
  105. Pentest Tools For Ubuntu
  106. Hacking Tools Software
  107. Hack Tools 2019
  108. Pentest Tools For Windows
  109. Nsa Hack Tools Download
  110. Hack Tools Mac
  111. Hacking Tools Windows 10
  112. Pentest Tools Github
  113. Computer Hacker
  114. Hack Tools For Mac
  115. Hacker Tools Github
  116. Hack And Tools
  117. Hacking Tools 2020
  118. Hacker Tool Kit
  119. Hacker Tools Mac
  120. Pentest Tools Tcp Port Scanner
  121. Best Pentesting Tools 2018
  122. New Hacker Tools
  123. Hack And Tools
  124. Hacking Tools Pc
  125. Pentest Tools Website
  126. Hacking Tools For Mac
  127. Hacker Tools Mac
  128. Tools For Hacker
  129. How To Install Pentest Tools In Ubuntu
  130. Hacker Tools Linux
  131. Hack Tools For Pc
  132. Pentest Tools Linux
  133. Hacking Tools For Windows
  134. Best Hacking Tools 2019
  135. Hacker Tools List
  136. Hacker
  137. Pentest Tools Review
  138. Pentest Tools Alternative
  139. Hacking Tools Github
  140. Hack Tools Download
  141. Hacking Tools For Pc
  142. Hacking Tools Download
  143. Github Hacking Tools
  144. Hacking Tools Windows 10
  145. Hack Tools Mac
  146. Pentest Tools Linux
  147. Pentest Tools Port Scanner
  148. Free Pentest Tools For Windows
  149. Free Pentest Tools For Windows
  150. Top Pentest Tools
  151. Termux Hacking Tools 2019
  152. Pentest Tools Port Scanner
  153. Hack Tools For Ubuntu
  154. Top Pentest Tools
  155. Pentest Tools List
  156. Hacker Tools For Mac
  157. Hacking Tools And Software
  158. Hacker Techniques Tools And Incident Handling
  159. Pentest Automation Tools
  160. Hak5 Tools
  161. Hack Website Online Tool
  162. Hacking Tools Windows 10
  163. Nsa Hack Tools
  164. How To Hack
  165. Hacker Tools Mac
  166. Hacker Tools Online
  167. Hacker Tools For Mac
  168. Hacking Tools Windows 10
  169. Hacker Tools Mac
  170. Best Hacking Tools 2020
  171. Pentest Tools Nmap
  172. Pentest Tools Nmap
  173. Hacker Tool Kit
  174. Computer Hacker
  175. Usb Pentest Tools
  176. Pentest Tools Framework

$$$ Bug Bounty $$$

What is Bug Bounty ?



A bug bounty program, also called a vulnerability rewards program (VRP), is a crowdsourcing initiative that rewards individuals for discovering and reporting software bugs. Bug bounty programs are often initiated to supplement internal code audits and penetration tests as part of an organization's vulnerability management strategy.




Many software vendors and websites run bug bounty programs, paying out cash rewards to software security researchers and white hat hackers who report software vulnerabilities that have the potential to be exploited. Bug reports must document enough information for for the organization offering the bounty to be able to reproduce the vulnerability. Typically, payment amounts are commensurate with the size of the organization, the difficulty in hacking the system and how much impact on users a bug might have.


Mozilla paid out a $3,000 flat rate bounty for bugs that fit its criteria, while Facebook has given out as much as $20,000 for a single bug report. Google paid Chrome operating system bug reporters a combined $700,000 in 2012 and Microsoft paid UK researcher James Forshaw $100,000 for an attack vulnerability in Windows 8.1.  In 2016, Apple announced rewards that max out at $200,000 for a flaw in the iOS secure boot firmware components and up to $50,000 for execution of arbitrary code with kernel privileges or unauthorized iCloud access.


While the use of ethical hackers to find bugs can be very effective, such programs can also be controversial. To limit potential risk, some organizations are offering closed bug bounty programs that require an invitation. Apple, for example, has limited bug bounty participation to few dozen researchers.
Related links

August Connector

OWASP
Connector
  August 2019

COMMUNICATIONS


Letter from the Vice-Chairman:

Dear OWASP Community,  

I hope you are enjoying your summer, mines been pretty busy, getting married, traveling to Vegas and the board elections. August has been quite a busy month for the foundation. Attending BlackHat and DefCon as part of our outreach program, the upcoming elections ( I have to add, there were some really good questions from the community) and planning for the next two Global AppSec Conferences in September, it's been crazy. We the board would like to thank the staff and without naming any names (Jon McCoy) for their efforts during BlackHat and DefCon. I was there, on the stand, he did a good job of representing our community.

Two days prior to BlackHat and Defcon the board met as part of our second face to face meeting of the year. This was two days well spent, collaborating on some of the burning topics, but also how to move forward. At the beginning of the year, we set out our strategic goals. Even though these goals are part of our everyday OWASP life we decided to put a name against them to champion them, below are our goals and who will be championing them going forward:

Marketing - Chenxi
Membership - Ofer
Developer Outreach - Martin
Project Focus - Sherif
Improve Finances - Gary
Perception - Martin 
Process Improvement - Owen
Consistent ED - Done! 
Community Empowerment - Richard

If you are interested in getting involved in or would like to hear more about any of these strategic goals, please reach out to the relevant name above. 

Some of the Global board members will be attending both our Global AppSec Conference in Amsterdam but also in DC. We will hold our next public board meeting during the Global AppSec Conference in Amsterdam if you haven't already done so I would encourage you to both attend and spread the word of the conference. There are some great keynotes/ speakers and trainers lined up. 

Regards
Owen Pendlebury 
Vice-Chairman of the OWASP Global Board of Directors
DC Registration Now Open                                   Amsterdam Registration Now Open
Congratulations to the Global AppSec Tel Aviv 2019
Capture the Flag Winners

 
For two full days, 24 competitors from around the world attacked various challenges that were present within the CTF activity held at Global AppSec Tel Aviv 2019. The competition began with a handful of competitors running neck and neck with two competitors, 4lemon and vasya, at the top, slowly gathering more points in their race hoping to win it all. At the last moment, they were overtaken by Aleph who swooped in and took away the victory for himself with a total score of 29 points! 

We would like to thank all of the individuals who participated and once again, congratulations to the top 3.
1st Place Winner: Aleph (29 points)
2nd Place: 4lemon (24 points)
3rd Place: vasya (24 points)

EVENTS 

You may also be interested in one of our other affiliated events:


REGIONAL EVENTS
Event DateLocation
OWASP Portland Training Day September 25, 2019 Portland, OR
OWASP Italy Day Udine 2019 September 27, 2019 Udine, Italy
OWASP Poland Day October 16,2019 Wroclaw, Poland
BASC 2019 (Boston Application Security Conference) October 19,2019 Burlington, MA
LASCON X October 24 - 25,2019 Austin, TX
OWASP AppSec Day 2019 Oct 30 - Nov 1, 2019 Melbourne, Australia
German OWASP Day 2019 December 9 - 10, 2019 Karlsruhe, Germany
AppSec California 2020 January 21 - 24. 2020 Santa Monica, CA
OWASP New Zealand Day 2020 February 20 - 21, 2020 Auckland, New Zealand

PARTNER AND PROMOTIONAL EVENTS
Event Date Location
it-sa-IT Security Expo and Congress October 8 - 10, 2019 Germany

PROJECTS


Project Review Results from Global AppSec - Tel Aviv 2019
The results of the project reviews from Global AppSec Tel Aviv 2019 are in!  The following projects have graduated to the indicated status:

Project Leaders Level
Mobile Security Testing Guide Jeroen Willemsen, Sven Schleier Flagship
Cheat Sheet Series Jim Manico, Dominique Righetto Flagship
Amass Jeff Foley Lab


Please congratulate the leaders and their teams for their achievements!
If your project was up for review at Global AppSec Tel Aviv 2019 and it is not on this list, it just means that the project did not yet receive enough reviews.  And, if you are interested in helping review projects, send me an email (harold.blankenship@owasp.com).

Project Showcases at the Upcoming Global AppSecs
The Project Showcases for Global Appsec DC 2019 and Global AppSec Amsterdam 2019 are finalized.  For a complete schedule, see the following links:

Global AppSec - DC 2019 Project Showcase
Global AppSec - Amsterdam 2019 Project Showcase


Google Summer of Code Update
Google Summer of Code is now in the final stages.  Final Evaluations are due by September 2nd.  


The Mentor Summit will be in Munich this year; congratulate the OWASP mentors who were picked by raffle to attend and represent OWASP: Azzeddine Ramrami & Ali Razmjoo.

Google Summer of Code Update

THE OWASP FOUNDATION HAS SELECTED THE TECHNICAL WRITER FOR GOOGLE SEASON OF DOCS by Fabio Cerullo

The OWASP Foundation has been accepted as the organization for the Google Seasons of Docs, a project whose goals are to give technical writers an opportunity to gain experience in contributing to open source projects and to give open-source projects an opportunity to engage the technical writing community.

During the program, technical writers spend a few months working closely with an open-source community. They bring their technical writing expertise to the project's documentation, and at the same time learn about open source and new technologies.

The open-source projects work with the technical writers to improve the project's documentation and processes. Together they may choose to build a new documentation set, or redesign the existing docs, or improve and document the open-source community's contribution procedures and onboarding experience. Together, we raise public awareness of open source docs, of technical writing, and of how we can work together to the benefit of the global open source community.

After a careful review and selection process, the OWASP Foundation has picked the primary technical writer who will work along the OWASP ZAP Team for the next 3 months to create the API documentation of this flagship project.

Congratulations to Nirojan Selvanathan!

Please refer to the linked document where you could look at the deliverables and work execution plan.
https://drive.google.com/open?id=1kwxAzaqSuvWhis9Xn1VKNJTJZPM2UV20

COMMUNITY

 
Welcome New OWASP Chapters

Tegucigalpa, Honduras
Johannesburg, South Africa
 

CORPORATE SPONSORS


 
Join us
Donate
Our mailing address is:
OWASP Foundation 
1200-C Agora Drive, #232
Bel Air, MD 21014  
Contact Us
Unsubscribe






This email was sent to *|EMAIL|*
why did I get this?    unsubscribe from this list    update subscription preferences
*|LIST:ADDRESSLINE|*