Pages

Tuesday, 1 March 2016

SSLv2 DROWN Attack Alert

US-CERT Publish New SSL2 Alert
Network traffic encrypted using an RSA-based SSL certificate may be decrypted if enough SSLv2 handshake data can be collected. Exploitation of this vulnerability - referred to as DROWN in public reporting - may allow a remote attacker to obtain the private key of a server supporting SSLv2. US-CERT encourages users and administrators to review Vulnerability Note VU#583776 and the US-CERT OpenSSL Current Activity for additional information and mitigation details.

Accordingly to Drownattack Web Site about 33% of Worldwide websites  Vulnerable
Full Technical Paper available on here DROWN:BREAKING TLS using SSLv2

1 comment:

  1. Ayoze-Gaming | Casino Games | JT Hub
    JT Games is 강원도 출장안마 an international, multi-faceted entertainment destination 강원도 출장샵 located 통영 출장안마 on the northern edge of the world of Asia and 제천 출장안마 Southeast Asia. 경산 출장마사지 JT Games is a

    ReplyDelete