phpbb and sql errors asp sqlserver odbc sql errors

Today´s Diary

If you have more information or corrections regarding our diary, click here to contact us.

Published: 2009-11-06,
Last Updated: 2009-11-06 22:43:05 UTC
by Andre Ludwig (Version: 1)
2 comment(s) Facebookacebook witter


Due to the recent publishing of information regarding a TLS/SSL protocol vulnerability (previous ISC diary entry can be found here http://isc.sans.org/diary.html?storyid=7534)  OpenSSL has released a new version (OpenSSL 0.9.8l). It should be noted that this update does not "fix" the vulnerability in the protocol. It appears that they have made the choice to simply remove TLS/SSL renegotiation from their package by default.  I would urge  anyone who is running a SSL enabled site that uses OpenSSL to thoroughly test their application as well as any software clients that are in used with their application.  There has been some discussion on the effects of simply removing renegotiation from these packages or disabling them by default (as OpenSSL has done). There will no doubt be instances where clients/servers will cease to function properly when renegotiation is disabled or removed.  The nice thing about what OpenSSL has done is if you do run into issues, it appears to be an easy fix (set a flag and -hup!).  So as always make sure to test vigorously before you deploy!

You can get this new version of OpenSSL at the link below.

http://www.openssl.org/source/


Release note from OpenSSL package:

    Disable renegotiation completely - this fixes a severe security
    problem (CVE-2009-3555) at the cost of breaking all
    renegotiation. Renegotiation can be re-enabled by setting
    SSL3_FLAGS_ALLOW_UNSAFE_LEGACY_RENEGOTIATION in s3->flags at
    run-time. This is really not recommended unless you know what
    you're doing.
    [Ben Laurie]

This event will no doubt develop over the next coming weeks and months, it should be interesting to see how far research goes into other protocols that ride on top of TLS/SSL channels. Let us not forget that not all traffic that is TLS/SSL encrypted is HTTP. Just off the top of my head I can think of LDAP, MSSQL, Email, and let us not forget SSL VPNS!  Since this is a bug in a low lying protocol that higher level applications/protocols rely on there will no doubt be allot of interest issues raised. No doubt plenty of people including myself will have a busy weekend rereading the TLS specification.  For those who are bored, feel free to read that specification at the URL below. 

 TLS 1.0:  http://www.ietf.org/rfc/rfc2246.txt

SSL 3.0: http://tools.ietf.org/html/draft-ietf-tls-ssl-version3-00

 

Andre Ludwig

Keywords: Openssl SSL tls
2 comment(s) Facebookacebook witter
A new version of Firefox (3.5.5) just became available. According to the release notes they are stability improvements.
Published: 2009-11-05,
Last Updated: 2009-11-06 02:06:38 UTC
by Swa Frantzen (Version: 1)
0 comment(s) Facebookacebook witter

Affected: BlackBerry Desktop Software version 5.0 and earlier (on all platforms) - IBM Lotus Notes Intellisync

Fixed in version 5.01

CVSS score: 9.3

CVE-2009-0306

More info: KB19701

The KB contains a workaround for those not eeding the Lotus Notes Intellisync functionality.

Thanks to Greg for sending this in.

--
Swa Frantzen -- Section 66

0 comment(s) Facebookacebook witter

If you have more information or corrections regarding our diary, click here to contact us.

Diary Archive

DateAuthorTitle
2009-11-06Andre Ludwig New version of OpenSSL released - OpenSSL 0.9.8l
2009-11-05Swa Frantzen Legacy systems
2009-11-05Swa Frantzen Insider threat: The snapnames case
2009-11-05Swa Frantzen TLS Man-in-the-middle on renegotiation vulnerability made public
2009-11-05Swa Frantzen RIM fixes random code execution vulnerability
2009-11-03Andre Ludwig SURBL now posting abuse statistics for TLD's
2009-11-03Bojan Zdrnja Opachki, from (and to) Russia with love
2009-11-02Daniel Wesemann Password rules: Change them every 25 years
2009-11-02Rob VandenBrink Microsoft releases v1.02 of Enhanced Mitigation Evaluation Toolkit (EMET)
2009-11-02Daniel Wesemann IDN ccTLDs
Complete Archive
Search Diaries:

StormCast


last update 05 hrs 02 min ago.

Featured Event

Latest Reading Room Papers

Why Crack When You Can Pass the Hash?
A Fuzzing Approach to Credentials Discovery using Burp Intruder
Women in IT Security Project Management
Security Concerns in Using Open Source Software for Enterprise Requirements
Harness the Power of SIEM

Poll

I back up data on my home PCs...
daily, or whenever files change or get added
once a week
once a month
every now and then
other (please leave comment)

Trends

trends more details

World Map

Worldmap