Latest Comments
"I urge every business person and IT person, management or staff, to get hold of a copy of "I.T. ..."
by John Franks | Sep 6, 2008 1:20 AM
 
"iam intrested in porn movies workes in actors from 36/m india pleas help me thanks."
by vinod agarwal | Sep 5, 2008 8:26 PM
 
"test for intresting"
by cocoboy | Sep 5, 2008 5:39 PM
 
"It's great that Google have recognised that security needs to be an important consideration with ..."
by Lloyd Borrett | Sep 5, 2008 11:53 AM
 
""Google arrived on the browser scene with the launch of Chrome"... Seems a bit misplaced to ..."
by Jeme | Sep 5, 2008 12:33 AM

Debian random key generator flaw could persist

  • Email a Friend
  • Print Page
By Dan Kaplan
May 21, 2008 8:55 AM
Tags: Debian | random | key | generator | flaw | could | persist
“We'll keep seeing buggy SSL and SSH keys,” H.D. Moore, director of security research for BreakingPoint Systems and creator of the Metasploit framework, told SCMagazineUS.com. “It's hard to [fix] every single list of keys on every single box.”

The bug is caused by a weakness in the random number generator used to create SSL and SSH public and private cryptographic keys, used to secure website traffic.

The random generator only results in about 32.767 possible keys, which could be cracked using a tactic known as brute force, in which every possible password is tried, said Moore, who has released an automated tool for cracking the keys.

Exploiting the hole could result in an attacker intercepting customer traffic without them knowing, experts said.

“As a result of the vulnerability, the keys generated using the flawed OpenSSL package may be weak,” a US-CERT advisory said last week. “Exploitation of these vulnerabilities may allow a remote, unauthenticated attacker to conduct brute force attacks and obtain sensitive information.”

Moore said administrators should use a scanning tool to look for vulnerable keys that make up a blacklist, published by the Debian Project.

Meanwhile, SSL certificate provider VeriSign said Monday that it is launching a free program that will revoke and replace any SSL, code signing or client certificate. The offer runs through June 30.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Vulnerabilities & Exploits Whitepapers