Skip to content
Attacks on the TLS Record Protocol and IT Certification Exams
  • Contact Us
Close Menu

TIME – Attacks on the TLS Record ProtocolTIME – Attacks on the TLS Record Protocol

11/15/202211/15/2022| Vera NeelTIME – Attacks on the TLS Record Protocol| 0 Comment| 03:58

21.5.5 TIME Less than a year after CRIME was published, security researchers Tal Be’ery and Amichai Shulman presented a new attack they called Timing Info-leak Made Easy (TIME) [17]. Conceptually, [...]

Read MoreRead More

BREACH – Attacks on the TLS Record ProtocolBREACH – Attacks on the TLS Record Protocol

09/02/202209/02/2022| Vera NeelBREACH – Attacks on the TLS Record Protocol| 0 Comment| 03:58

21.5.6 BREACH In the second half of 2013, security researchers Yoel Gluck, Neal Harris, and Angelo Prado published a modification of CRIME that they called Browser Reconnaissance and Exfiltration via [...]

Read MoreRead More

HEIST – Attacks on the TLS Record ProtocolHEIST – Attacks on the TLS Record Protocol

07/10/202207/10/2022| Vera NeelHEIST – Attacks on the TLS Record Protocol| 0 Comment| 03:59

21.5.7 HEIST In 2016, Mathy Vanhoef and Tom Van Goethem, two security researchers from Belgium, published yet another attack on TLS that exploits the compression side channel. They called their [...]

Read MoreRead More

SMACK – Attacks on TLS ImplementationsSMACK – Attacks on TLS Implementations

05/10/202205/10/2022| Vera NeelSMACK – Attacks on TLS Implementations| 0 Comment| 04:31

22.1 SMACK In 2015, a group of French security researchers with Benjamin Beurdouche systematically tested the then-popular open source TLS implementations for state-machine-related bugs and uncovered multiple critical security vulnerabilities [...]

Read MoreRead More

FREAK – Attacks on TLS ImplementationsFREAK – Attacks on TLS Implementations

03/05/202203/05/2022| Vera NeelFREAK – Attacks on TLS Implementations| 0 Comment| 04:32

22.2 FREAK FREAK stands for Factoring RSA Export Keys. The attack was discovered in 2017 ([27]) and can be seen as a variant of the cipher suite downgrade attack shown [...]

Read MoreRead More

Heartbleed – Attacks on TLS ImplementationsHeartbleed – Attacks on TLS Implementations

01/02/202201/02/2022| Vera NeelHeartbleed – Attacks on TLS Implementations| 0 Comment| 04:33

22.4 Heartbleed In 2014, Google’s security team member Neel Mehta privately reported an implementation bug to OpenSSL’s developer team. The same bug was independently discovered by security engineers working for [...]

Read MoreRead More

he Heartbleed bug – Attacks on TLS Implementationshe Heartbleed bug – Attacks on TLS Implementations

11/12/202111/12/2021| Vera Neelhe Heartbleed bug – Attacks on TLS Implementations| 0 Comment| 04:36

22.4.2 The Heartbleed bug Heartbleed is the result of improper input validation – more precisely, a missing bounds check – in the OpenSSL implementation of the TLS Heartbeat extension. Technically, [...]

Read MoreRead More

The bugfix – Attacks on TLS ImplementationsThe bugfix – Attacks on TLS Implementations

10/02/202110/02/2021| Vera NeelThe bugfix – Attacks on TLS Implementations| 0 Comment| 04:38

22.4.3 The bugfix The bugfix for the Heartbleed bug is shown in Listing 22.3. It is a simple bounds check using the actual TLS record length in the s3-¿rrec data [...]

Read MoreRead More

Random number generation – Attacks on TLS ImplementationsRandom number generation – Attacks on TLS Implementations

08/02/202108/02/2021| Vera NeelRandom number generation – Attacks on TLS Implementations| 0 Comment| 04:39

22.6 Random number generation In Chapter 3 A Secret to Share, we learned that the security of most protocols and mechanisms depends on the generation of random sequences of bits [...]

Read MoreRead More

Cloudbleed – Attacks on TLS ImplementationsCloudbleed – Attacks on TLS Implementations

07/08/202107/08/2021| Vera NeelCloudbleed – Attacks on TLS Implementations| 0 Comment| 04:40

22.8 Cloudbleed In 2017, Tavis Ormandy, a vulnerability researcher in Google’s Project Zero team, reported a security vulnerability in Cloudflare’s edge servers [76]. Cloudflare is a large Content Delivery Network [...]

Read MoreRead More

Posts pagination

Previous 1 2 3 Next

Search

Dropdown Categories

Archives

  • September 2024
  • April 2024
  • February 2024
  • December 2023
  • October 2023
  • August 2023
  • June 2023
  • April 2023
  • February 2023
  • November 2022
  • September 2022
  • July 2022
  • May 2022
  • March 2022
  • January 2022
  • November 2021
  • October 2021
  • August 2021
  • July 2021
  • May 2021
  • March 2021
  • January 2021

Meta

  • Log in

Tag Cloud

Back to Top
Privacy Policy | Cookie Policy | Cookies Settings | Terms & Conditions | Accessibility | Legal Notice