Hackers expose weakness in visiting trusted sites

August 2, 2009 By JORDAN ROBERTSON , AP Technology Writer

(AP) -- A powerful new type of Internet attack works like a telephone tap, except operates between computers and Web sites they trust.

Hackers at the Black Hat and DefCon security conferences have revealed a serious flaw in the way Web browsers weed out untrustworthy sites and block anybody from seeing them. If a criminal infiltrates a network, he can set up a secret eavesdropping post and capture credit card numbers, passwords and other flowing between computers on that network and sites their browsers have deemed safe.

In an even more nefarious plot, an attacker could hijack the auto-update feature on a victim's computer, and trick it into automatically installing malware pulled in from a hacker's Web site. The computer would think it's an update coming from the software manufacturer.

The attack was demonstrated by three hackers. Independent security researcher Moxie Marlinspike presented alone, while Dan Kaminsky, with Seattle-based security consultancy IOActive Inc., and security and privacy researcher Len Sassaman presented together.

They reached essentially the same conclusion: There are major problems in the way browsers interact with Secure Sockets Layer (SSL) certificates, which is a common technology used on banking, e-commerce and other sites handling sensitive data.

Browser makers and the companies that sell SSL certificates are working on a fix.

Corp., whose browser is the world's most popular, said it was investigating the issue. Mozilla Corp., which makes the No. 2 Firefox browser, said most of the problems being addressed were fixed in the latest version of its browser, and that the rest will be fixed in an update coming this week.

VeriSign Inc., one of the biggest SSL certificate companies, maintains that its certificates aren't vulnerable.

Tim Callan, a product marketing executive in VeriSign's SSL business unit, added that the "tap" won't work against so-called Extended Validation SSL certificates, which cost more and involve a deeper inspection of a company's application for a certificate.

The attack falls into a class of hacks known as "man-in-the-middle," in which a criminal plants himself between a victim's computer and a legitimate Web site and steals data as it moves back and forth.

Jeff Moss, founder of the and Defcon conferences who this summer was appointed to the Homeland Security Department's advisory council, said the fact a hacker has to actually break into a victim's network for the attack to work can limit its usefulness.

"That's the nice mitigating thing," he said.

But he warned that "for targeted attacks it's absolutely deadly. This is the way you can get everything. If you can get in the middle, you can get everything. It's a big, giant wake-up call for the industry."

SSL certificates are a critical technology in assigning trust on the Web.

Sites buy them to encrypt traffic and assure visitors it's OK to enter confidential information. Companies that sell SSL certificates verify that someone trying to buy a certificate actually owns the site that certificate will be attached to.

The presence of an SSL certificate on a site is designated by a padlock in the address bar. But many people don't pay attention to whether a padlock is present or not.

Browsers do care, though, which is why this week's talks were significant.

Browsers are programmed to block sites that don't have a valid SSL certificate, or have a certificate displaying a Web address that doesn't match the address a Web surfer was trying to reach (which can indicate someone has hijacked a person's Internet session). If the sites aren't blocked, users are warned about potential danger, and have the option to click through.

The problems outlined by researchers center on a quirk in the way browsers read SSL certificates.

Many SSL certificate companies will allow people to attach a programming symbol called a "null character" into the Web address onto the certificates they receive. Web browsers generally ignore that symbol. They stop reading at that symbol when they're checking the Web address on a certificate.

The trick in the latest type of attack is that all a criminal would need to do is put the name of a legitimate Web site before that character, and the browser will believe that the site it's visiting - which is under the criminal's control - is legitimate.

The criminal could then forward the traffic onto the legitimate site and spy on everything the victim does on that site. It's a complicated attack, but it highlights a significant weakness in the very technology widely used to assure people it's safe to navigate sensitive sites.

Jon Miller, an SSL expert and director of Accuvant Labs, said he expects significant attacks against corporations using this technique in the coming months. Criminals who run "phishing" scams, in which people are tricked into visiting phony sites, will also likely latch on.

"What kind of makes this earth-shattering is these aren't the most sophisticated attacks in the world," he said. "This is going to become a huge problem."

There are signs it's already starting.

VeriSign's Callan said within hours of the talks, his company got a number of applications for SSL certificates featuring null characters, but they were denied.

©2009 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 4.8 /5 (13 votes)

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • CSharpner - Aug 02, 2009
    • Rank: 4 / 5 (1)
    Crap! Just a freaking null character and the browser(s) don't look any further? I hope the SSL cert authorities give notices to all cert owners with nulls that they'll be disabled, then actually disable them. The browser makers need to get this fix out ASAP!
  • gwrede - Aug 03, 2009
    • Rank: 5 / 5 (1)
    The perils of the null character have been known to industry ever since the first crackers emerged. And that's decades ago.

    It is a shame that most critical software today is still being developed in C/Cplusplus.[1] This affects the mind set of the programmer, as he daily works with null terminated strings.

    It is high time for the industry to move on to newer languages (for example D), that are robust, more efficient, and inherently offer a better level of security.

    Currently a programmer fights with pointer based data manipulation, language quirks, corner cases, gotchas and the like -- and all this means brain cells are devoted to things other than the actual task at hand. And the bosses aren't aware of the enormous difference in productivity, simply because "it's always been like this". They've never seen what it could/should be.

    -----------

    [1] Seems the pluses didn't stick, so I had to spell them out. !!
  • KCD - Aug 03, 2009
    • Rank: not rated yet
    Whoa! So that's how hackers get information that fast!
    Well, there's something that the browser(s) can fix immediately for the people's safety.
  • Ricochet - Aug 04, 2009
    • Rank: not rated yet
    Yeah, there's a reason they use ADA for the software in aviation...

August 2, 2009 all stories

Comments: 4

4.8 /5 (13 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • System thwarts Internet eavesdropping
    created Aug 25, 2008 | popularity not rated yet | comments 0
  • Experts uncover weakness in Internet security
    created Dec 30, 2008 | popularity not rated yet | comments 0
  • The Web: Mobsters extinguish firewalls
    created May 03, 2006 | popularity not rated yet | comments 0
  • Tips for Staying Safe on the Internet
    created Nov 03, 2005 | popularity not rated yet | comments 0
  • Security flaws in online banking sites found to be widespread
    created Jul 23, 2008 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Trying to adapt a fuel gage circuit
    created 5 hours ago
  • Pushing the piston.
    created 10 hours ago
  • Do Camcorders/ Video camera have Sensors in them?
    created 15 hours ago
  • Aspiring Engineering major looking for general answers
    created Nov 19, 2009
  • Calculating max load of square tube (steel)
    created Nov 19, 2009
  • Passive Chemical Heating
    created Nov 19, 2009
  • More from Physics Forums - General Engineering

Other News

China is the world's largest emitter of the greenhouse gases blamed for global warming

China harnesses mountain wind power

Technology / Energy

created 21 hours ago | popularity 4.1 / 5 (7) | comments 1

In the mountains above the southwestern Chinese town of Dali, dozens of new wind turbines dot the landscape -- a symbol of the country's sky-high ambitions for clean, green energy.


Newspaper circulation may be worse than it looks (AP)

Newspaper circulation may be worse than it looks

Technology / Internet

created 11 hours ago | popularity not rated yet | comments 0

(AP) -- While U.S. newspapers are losing subscribers at a staggering rate, a few dailies stand out because their circulation is rising. But they aren't necessarily selling more copies.


Canadian woman loses benefits over Facebook photo

Technology / Internet

created 12 hours ago | popularity 5 / 5 (1) | comments 0

(AP) -- A Canadian woman on long-term sick leave for depression says she lost her benefits because her insurance agent found photos of her on Facebook in which she appeared to be having fun.


Analysts say AmEx is most interested in the so-called peer-to-peer services of Revolution

American Express takes aim at PayPal with Revolution

Technology / Internet

created 18 hours ago | popularity 4.5 / 5 (2) | comments 1

With its deal to buy Revolution Money, American Express is taking aim at the growing market for online and alternative payments, in a challenge to recognized leader PayPal, analysts say.


Hackers leak e-mails, stoke climate debate

Technology / Internet

created Nov 21, 2009 | popularity 4.3 / 5 (34) | comments 27

(AP) -- Computer hackers have broken into a server at a well-respected climate change research center in Britain and posted hundreds of private e-mails and documents online - stoking debate over whether some scientists have ...