‏إظهار الرسائل ذات التسميات Freak SSL Vulnerability. إظهار كافة الرسائل
‏إظهار الرسائل ذات التسميات Freak SSL Vulnerability. إظهار كافة الرسائل

الخميس، 2 أبريل 2015

FREAK Attack: How to Protect Yourself







The recently disclosed FREAK (Factoring attack on RSA Export Keys) attack is an SSL/TLS vulnerability that is affecting major browsers, servers and even mobile devices. 



FREAK vulnerability allows the attacker to intercept HTTPS connections between vulnerable clients and servers and force them to use weakened encryption, which the attacker can break to manipulate or steal sensitive data.

الأربعاء، 18 مارس 2015

OpenSSL to Patch High Severity Vulnerability this Week





The OpenSSL Foundation is set to release a handful of patches for undisclosed security vulnerabilities in its widely used open source software later this week, including one that has been rated "high" severity.



In a mailing list note published last night, Matt Caswell of the OpenSSL Project Team announced that OpenSSL versions 1.0.2a, 1.0.1m, 1.0.0r, and 0.9.8zf will be released Thursday.

الأربعاء، 11 مارس 2015

Microsoft patches Stuxnet and FREAK Vulnerabilities





Microsoft has come up with its most important Patch Tuesday for this year, addressing the recently disclosed critical the FREAK encryption-downgrade attack, and a separate five-year-old vulnerability leveraged by infamous Stuxnet malware to infect Windows operating system.



Stuxnet malware, a sophisticated cyber-espionage malware allegedly developed by the US Intelligence and Israeli

الجمعة، 6 مارس 2015

Microsoft: All Windows versions Vulnerable to FREAK Vulnerability





Recently discovered FREAK vulnerability that apparently went undetected for more than a decade is reportedly affecting all supported versions of Microsoft Windows, making the flaw more creepy than what we thought.



FREAK vulnerability is a disastrous SSL/TLS flaw disclosed Monday that allows an attacker to force SSL clients, including OpenSSL, to downgrade to weaken ciphers that can be

الثلاثاء، 3 مارس 2015

'FREAK' — New SSL/TLS Vulnerability Explained





Another new widespread and disastrous SSL/TLS vulnerability has been uncovered that for over a decade left Millions of users of Apple and Android devices vulnerable to man-in-the-middle attacks on encrypted traffic when they visited supposedly 'secured' websites, including the official websites of the White House, FBI and National Security Agency.



Dubbed the "FREAK" vulnerability (