Home / News

Researchers Demonstrate How to Launch Undetectable Phishing Attacks

Researchers Demonstrate How to Launch Undetectable Phishing Attacks

With the help of about 200 Sony Playstations, an international team of security researchers have devised a way to undermine the algorithms used to protect secure Web sites and launch a nearly undetectable phishing attack.

To do this, they've exploited a bug in the digital certificates used by Web sites to prove that they are who they claim to be. By taking advantage of known flaws in the MD5 hashing algorithm used to create some of these certificates, the researchers were able to hack Verisign's RapidSSL.com certificate authority and create fake digital certificates for any Web site on the Internet.

Read full story: Network World

Updates:  UPDATED Jan 05, 2009 11:57 AM PST
MD5 considered harmful today Official Report
One Weak Link to Rule Them All Brian Krebs, Security Fix
The (Not Quite) End Of Security On The Internet George Hulme, InformationWeek
SSL broken! Hackers create rogue CA certificate using MD5 collisions ZDNet
So you can fake your SSL Certificate. That don’t impress me much Aviram Jenik, SecuriTeam
Verisign Discontinues Flawed MD5 Certificates ChannelWeb
The Problem With HTTPS SSL Runs Deeper Than MD5 George Ou, CircleID
MD5 Hack Interesting, But Not Threatening Tim Callan, SecurityFocus
The new MD5/SSL exploit is NOT the end of civilization as we know it Tom Olzak, TechRepublic

Related topics: Cyberattack, Cybercrime, Security

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

MarkMonitor to Exhibit at Internet Tech Policy Exhibition and Reception to be Held on Capitol Hill

Verisign to Award New Infrastructure Research Grants

Nixu SNS 2.5 Series Gives Fresh Views on DNS

Neustar Names Joe Pasqua to Head Neustar Labs

Q3 2011 Fraud Intelligence Report

The Spookiest DDoS Attacks in History

Protecting Your Business from DDoS Attacks: Advice from Neustar

A Different Kettle of Phish

Introduction to Nixu Software: End-to-End Software-Based DNS, DHCP, IPAM Solutions for Your Network

MarkMonitor Fraud Intelligence Report Released for Q2 2011

President Obama Names Neustar President and CEO Lisa Hook to NSTAC

Verisign's Matt Larson Wins 2011 InfoWorld Technology Leadership Award

Internet Adds 4.5 Million Domain Names in First Quarter of 2011

Businesses Lack Safeguards Against DDoS Attacks and DNS Failures, New Research Shows

Q1 2011 Fraud Intelligence Report

Neustar Launches SiteProtect for DDoS Protection

The Botnet-Counterfeit Drugs Connection

Verisign Enhances Its Managed DNS Service With Full Support for DNSSEC Compliance and Geo Location

Verisign Achieves Critical DNSSEC Milestone by Deploying Security Extensions in .com TLD

New Verisign Uptime Bundle Combines DDoS Protection, Managed DNS and Threat Intelligence Services

Hot Topics

Verisign

Security

Sponsored by
Verisign
Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines
Afilias

DNSSEC

Sponsored by
Afilias
Neustar UltraDNS

DNS

Sponsored by
Neustar UltraDNS
dotMobi

Mobile

Sponsored by
dotMobi