اطلاعیه

Collapse
No announcement yet.

mod_ssl timing based attack Çíäã ÂÎÑíÔ

Collapse
X
 
  • Filter
  • زمان
  • Show
Clear All
new posts

  • mod_ssl timing based attack Çíäã ÂÎÑíÔ

    mod_ssl timing based attack
    A timing attack on RSA keys exists, to which OpenSSL is vulnerable, unless RSA
    blinding has been turned on. With this package, mod_ssl is secured even if OpenSSL is
    not.

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    [slackware-security] mod_ssl RSA blinding fixes (SSA:2003-141-05)

    An upgrade for mod_ssl to version 2.8.14_1.3.27 is now available.
    This version provides RSA blinding by default which prevents an
    extended timing analysis from revealing details of the secret key
    to an attacker. Note that this problem was already fixed within
    OpenSSL, so this is a "double fix". With this package, mod_ssl
    is secured even if OpenSSL is not.

    We recommend sites using mod_ssl upgrade to this new package.


    Here are the details from the Slackware 9.0 ChangeLog:
    +--------------------------+
    Tue May 20 2009 PDT 2003
    patches/packages/mod_ssl-2.8.14_1.3.27-i386-1.tgz: Upgraded to
    mod_ssl-2.8.14_1.3.27. Includes RSA blinding fixes.
    (* Security fix *)
    +--------------------------+



    WHERE TO FIND THE NEW PACKAGES:
    +-----------------------------+

    Updated package for Slackware 9.0:
    ftp://ftp.slackware.com/pub/slackwar....27-i386-1.tgz



    MD5 SIGNATURES:
    +-------------+

    Slackware 9.0 package:
    2888ecec5e2116be81b5295fc477869b mod_ssl-2.8.14_1.3.27-i386-1.tgz



    INSTALLATION INSTRUCTIONS:
    +------------------------+

    First, shut down your web server:
    # apachectl stop

    Then upgrade using upgradepkg (as root):
    upgradepkg mod_ssl-2.8.14_1.3.27-i386-1.tgz

    Finally, restart secure web services:
    # apachectl startssl



    +-----+

    Slackware Linux Security Team
    http://slackware.com/gpg-key
    [email protected]

    +------------------------------------------------------------------------+
    | HOW TO REMOVE YOURSELF FROM THIS MAILING LIST: |
    +------------------------------------------------------------------------+
    | Send an email to [email protected] with this text in the body of |
    | the email message: |
    | |
    | unsubscribe slackware-security |
    | |
    | You will get a confirmation message back. Follow the instructions to |
    | complete the unsub******ion. Do not reply to this message to |
    | unsubscribe! |
    +------------------------------------------------------------------------+

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.2 (GNU/Linux)

    iD8DBQE+zBCIakRjwEAQIjMRApK5AJ9MQaXY1zM+sB65F+01L3 1jBY+WEwCdHt5q
    MNjPi+EFkCpcS4ba0qwZZHg=
    =HMFX
    -----END PGP SIGNATURE-----
    http://blxk.shabgard.org

  • #2
    [f]
    dear Bl2k
    Ïیå ÞÑÇÑ äÔÏ ˜å ÇیäÌÇ ÈÔå securityfocus.com
    ÐÑ åÑ ÍÇá ÔãÇ ÏÇÑی ÒÍãÊ ãی˜Ôی . ããäæä .
    ÇãیÏæÇÑã åãå ÇیäÞÏÑ active ÈÔä


    [/f]
    .::..::..::..::..::..::..::..::..::..::.
    Connection reset by peer.
    .::..::..::..::..::..::..::..::..::..::.
    http://hkashfi.blogspot.com/

    Comment


    • #3
      Re: mod_ssl timing based attack Çíäã ÂÎÑíÔ

      ÓáÇã ãåäÏÓ

      ÂÞÇ ÑÇÓÊ ãíí Çíä ÓÇíÊåÇ ÎæÈ ÈÑæÒ ãØáÈ ãíÏä

      æáí ãíÏæäí..
      ãä íå ÚÇÏÊ ÏÇÑã åÑ æÞÊ ãíÇã ÇíäÊÑäÊ
      Çæá ãíá Ñæ ÊÇ Çæä ÈÇÒ Ôå ÓÇíÊ ÔãÇ ÓÇíÊ Âí Êí æ

      ÍÏæÏ 15 ÊÇ ÓÇíÊ ÎÈÑí.. ÓßíæÑÊí ..... ÎÈÑåÇí ÌÏíÏ æ äÇå ãíßäã.. ÇáÈÊå Çíäã Ȑã åãíÔå íÒÇí Îíáí ÌÏíÏ ÈÔã äãíÇä
      åãæä ÓÇíÊí ßå ÝÊí
      Security....
      åãíÔå ßÇÑ ÇÒ ßÇÑ ßå ÐÔÊå ÎÈÑÔæ ãíÏå æáí åãÔå Êæ ÑæååÇí ÎÈÑí ßå ÔÇíÏ È å ÒÈæä ÇÓÊÇäÏÇÑÏ åã äÈÇÔå ãíÇä

      ÎÏÇ ÑÍãÊ ßäå åÑ ßí Çíä ãÊÑÌ㠍äÏ ÒÈÇäÑæ äæÔÊå ßÇÑå ãäã ÑÇÍÊ ßÑÏå

      Îíáí ÎÈÑ ÈÇ ÈÑäÇãå åÓÊ ßå åäæÒã åí ÌÇ ÚäæÇä äÔÏå...


      ÈÚÖí íÒÇ Ñæ ÏæÓÊ ÏÇÔÊã Ȑã .. ÔÑãäÏå ÍÇá ÊÑÌãå ßÑÏä äÏÇÑã
      ÂÎå ÇäáíÓí Ííáí ÑÓÇÊÑ ÊÇ ãä ÈÎæÇã ÈÇ ÊÑÌãå ÈÏã ßå íßíã ÈÇíÏ ÈÔíäå ÊÑÌãå ßäå..


      :D

      ãåäÏÓ ãä Èå åãå ÚÒíÒÇä ÇÑÇÏÊ ÏÇÑã

      ÑÇÓÊí ÇÒ ÏæÓÊ ÎæÈãæä
      Shabgard9
      ÔÇíÏ ÈÇ Çí Ïí ÚæÖ ÔÏå ÇíäÌÇ ÎÈÑí åÓÊ



      ÈÞæá ÇÏãíä Ìæä

      C U L

      :D
      http://blxk.shabgard.org

      Comment

      Working...
      X