HNHacker News
TopNewBestAskShowJobs

c0r0n3r

377 karma · joined January 24, 2019

submissionscomments
c0r0n3r··on [dead]
Which TLS/cryptography analyzer is right for you?
c0r0n3r··on [dead]
Exploiting the computationally expensive nature of the Diffie-Hellman key exchange protocol an attacker can perform a denial-of-service (DoS) attack by sending arbitrary numbers as public keys to a target server forcing it to generate its public key, validate the peer's one, and compute the shared secret. All three operations require the computationally complex modular exponentiation which creates an asymmetric resource usage situation, which is the basis for overloading the server's CPU and rendering it unavailable. The attack is carried out with such a methodology called D(HE)at attack (CVE-2002-20001).
c0r0n3r··on An Analysis of the DHEat DoS Against SSH in Cloud Environments
Conclusion

"The DHEat attack remains viable against most SSH installations, as default settings are inadequate at deflecting it. Very little bandwidth is needed to cause a dramatic effect on targets, including those with a high degree of resources. Hence, SSH services should be blocked from external access whenever possible. Furthermore, connection rate limiting should always be applied regardless of network segmentation, as per the central principles of Zero Trust."

c0r0n3r··on Factorization (DCQF) of a 48-bit integer using 10 trapped-ion qubits
We factorize a 48-bit integer using 10 trapped-ion qubits on a Quantinuum’s quantum computer. This result outperforms the recent achievement by B. Yan et al., arXiv:2212.12372 (2022), increasing the success probability by a factor of 6 with a non-hybrid digitized-counterdiabatic quantum factorization (DCQF) algorithm. We expect better results with hybrid DCQF methods on our path to factoring RSA-64, RSA-128, and RSA-2048 in this NISQ era, where the latter case may need digital-analog quantum computing (DAQC) encoding.
c0r0n3r··on Chinese researchers: RSA is breakable. Others: Do not panic
Chinese researchers claim that there is an existing algorithm that, even with today's quantum computers, makes it possible to break the RSA algorithm. At the same time, there are doubts about the reliability of the publication. However, even if these doubts are confirmed, it does not change the fact that quantum computers pose security threat now.
c0r0n3r··on OpenSSL: How to Configure LS Groups to Be Resistant to the DHEat Attack
... The CVE-2002-20001 (a.k.a DHEat attack) vulnerability inherent to the support of the Diffie-Hellman (DH) and Elliptic Curve Diffie-Hellman (ECDH) key exchanges in TLS and other protocols provides a way for an attacker to cause high CPU usage on servers with relatively low effort on the client side. ...
c0r0n3r··on DHEat Attack: DoS attack by enforcing the Diffie-Hellman key exchange
You can also use CryptoLyzer[1] to audit your TLS (not just HTTPS, but SMTP, IMAP, ...) and SSH servers if you do not want to use SaaS solutions.

There are another tools (open source and SaaS) on OWASP Transport Layer Protection Cheat Sheet page[2].

[1] https://gitlab.com/coroner/cryptolyzer

[2] https://cheatsheetseries.owasp.org/cheatsheets/Transport_Lay...

c0r0n3r··on DoS attack against Diffie-Hellman protocol
The right URL is: https://dheatattack.com
c0r0n3r··on DoS attack against Diffie-Hellman protocol
Who is affected?

Websites, mail servers, and other Transport Layer Security (TLS) dependent services that support Diffie-Hellman key exchange using ephemeral keys (DHE cipher suites) are at risk of the DHEat attack. Services using other cryptographic protocols can also be affected.

* Secure Shell (SSH) services support Diffie-Hellman key exchange methods. * Internet Protocol Security (IPsec) services offer DH groups. * OpenVPN servers support Diffie-Hellman key exchange in the control channel (DHE TLS ciphers).

How bad is it?

The CVSS 3.1 base score of CVE-2002-20001 is 7.5, indicating high severity but is not critical. However, it should be mentioned that a denial-of-service attack affects only availability. Still, confidentiality, integrity, and scope are not is affected and cannot achieve a higher base score. However, an attacker can exploit the vulnerability and perform a denial-of-service attack with a low-bandwidth network connection without authentication, privilege, or user interaction. Along with the fact that this vulnerability cannot be fixed, as it exploits a particularity of the Diffie-Hellman key exchange algorithm, it can be mitigated in some ways.

c0r0n3r··on DoS attack against Diffie-Hellman protocol
Who is affected?

Websites, mail servers, and other Transport Layer Security (TLS) dependent services that support Diffie-Hellman key exchange using ephemeral keys (DHE cipher suites) are at risk of the DHEat attack. Services using other cryptographic protocols can also be affected.

* Secure Shell (SSH) services support Diffie-Hellman key exchange methods. * Internet Protocol Security (IPsec) services offer DH groups. * OpenVPN servers support Diffie-Hellman key exchange in the control channel (DHE TLS ciphers).

c0r0n3r··on A New Life for Certificate Revocation Lists
All the revocation checking mechanism have their pitfalls. It is a so complex issue. CRL has a very important benefit, namely it can be prefetched and can be updated regularly which is important in the case a firewall solution for instance. Read the following article for more details.

https://dev.to/coroner/why-do-certificate-revocation-checkin...

c0r0n3r··on Zorp – Open source proxy firewall with deep protocol analysis
3.2. Configuring TLS and SSL encrypted connections

https://www.balasys.hu/content/documents/zorp-gpl-guide-refe...