PDA

Archiv verlassen und diese Seite im Standarddesign anzeigen : [Global] More than 33 percent of all HTTPS servers are vulnerable to DROWN attack.



Bullsh1t
02.03.2016, 05:41
sorry für copy paste !


A new deadly security vulnerability has been discovered in OpenSSL that affects more than 11 Million modern websites and e-mail services protected by an ancient, long deprecated transport layer security protocol, Secure Sockets Layer (SSLv2). Dubbed DROWN, the highly critical security hole in OpenSSL was disclosed today as a low-cost attack that could decrypt your sensitive, secure HTTPS


ein ausführlicher artikel dazu:
http://thehackernews.com/2016/03/drown-attack-openssl-vulnerability.html

novedad
02.03.2016, 18:03
Auf Deutsch: http://www.golem.de/news/bleichenbacher-angriff-drown-entschluesselt-mit-uraltem-ssl-protokoll-1603-119457.html

SolSoCoG
04.03.2016, 10:06
Kleiner Tipp von mir: mbed TLS verwenden, hat keine Scheunentorcharakteristik, es steht 0:2.
Der Hiawatha Webserver verschlüsselt damit z.B.