+ Bookmark This Page    
Preferences  |  4:44 PM
  1. Home
  2. Latest Press Releases
  3. Submit Press Releases
  1. PR Home
  2. News Archive
  3. By Category
  4. By Location
  5. By Date
  6. By Tag
  7. Newsletter
  8. 40,000 RSS Feeds
  9. Submit Free Press Release
   
Filter News
Show All Results

Show Filtered Results

Category
- Marketing (x)

Country
- United States (x)

State / Province
- Puerto Rico (x)

City / Town
None Found
(To see all cities,
remove category filter)

Researchers Uncover Serious Flaw in Handling of Extended Validation SSL by Popular Browsers

Leading Security Experts Reveal How Users of EV SSL-Protected Websites are at Risk to Silent Man-In-The-Middle Attacks
 

FOR IMMEDIATE RELEASE

PRLog (Press Release)Jul 21, 2009 – New York, NY. – Intrepidus Group, a leading provider of information security services and software, today announced research that shows new short comings in browser designs that allow an attacker to silently “Man-In-The-Middle” (MITM) Extended Validation (EV) SSL-protected websites. Users of sites that appear to be secure through the “glow” of their green badge, have been found to be at risk of malicious attacks.

Research conducted by Mike Zusman, principal consultant at Intrepidus Group, and independent security researcher Alex Sotirov shows that a common web browser design flaw can be exploited to compromise SSL encrypted data, even when the user sees the green badge of EV SSL. The researchers have devised a new attack, called SSL Rebinding, which exploits this flaw to sniff sensitive data as it leaves the browser. Zusman and Sotirov have also demonstrated that the same flaw can be leveraged to launch browser cache poisoning attacks against EV SSL protected web sites. Both attacks can cause significant exposure and silently expose “encrypted” sessions protected by an EV SSL certificate.

o SSL Rebinding is an attack against an SSL involving a rogue MITM server which uses a combination of SSL certificates to manipulate client behavior and bypass security mechanisms.

o EV Cache Poisoning is a persistent attack, where cached content of an EV SSL protected web site can be poisoned without the victim consciously browsing the site.

“Verifying the “green glow” of EV SSL in the browser has often been pitched as the silver bullet to thwarting phishing attacks,” said Rohyt Belani, CEO of Intrepidus Group. “Our research shows that the green glow can be misleading and provide a false sense of security. Employees and customers should be provided a holistic perspective on phishing to best train them to be resilient to this ever-growing threat.”

Zusman and Sotirov will present the details of their research findings during the Back Hat USA 2009 Briefings & Training conference. Intrepidus Group has also enhanced its PhishMe solution to empower individuals to identify these attacks and protect themselves from cybercrime exposure.

Black Hat USA 2009 Briefings & Training Presentation
Mike Zusman and Alexander Sotirov will be sharing details of this new research on EV SSL Attacks during the Back Hat USA 2009 Briefings & Training conference, at Caesar’s Palace in Las Vegas, Nev. Their session will be held on “Day 2,” July 30, 2009 in the “//random” track from 3:15 to 4:30 p.m.

About PhishMe
PhishMe is a software-as-a-service (SaaS) solution designed to help prevent damage, theft and loss caused by targeted (spear) phishing attacks. PhishMe facilitates and automates the execution of mock phishing exercises against employees, provides clear and accurate reporting on user behavior, and most importantly provides instant, targeted employee training. This method of delivering training materials is recommended by SANS and found to be most effective by researchers at Carnegie Mellon University.

About Intrepidus
Intrepidus Group is a leading provider of information security consulting services and software solutions. With offices in New York City and the Washington DC metro area, the company offers innovative solutions to help clients build employee awareness around common information security issues. Intrepidus Group’s consultants also conduct hands-on assessments of critical applications, networks and products to uncover vulnerabilities, and provide strategic and tactical recommendations to address identified issues. Intrepidus Group One Penn Plaza, Suite 6180, New York, New York 10119
intrepidusgroup.com

END

PhishMe.com is a registered trademark of Intrepidus Group. All other product and company names herein are or may be trademarks of their respective owners.

To embed this press release, copy and paste the following HTML code into your webpage-
# # # Click to see PDF Version of this Press Release

Email to a Friend       Previous News   Next News


Email Contact:Click to email (Partial email =  @ventanapr.com) Email Verified
Issued By:Derek Kol
Phone:818-681-9400
Address:4929 Rigoletto
City/Town:Los Angeles
State/Province:California
Zip:91364
Country:United States
Categories:Computers
Tags:phish, email, security
Last Updated:Jul 21, 2009
Shortcut:http://prlog.org/10288494

Disclaimer:   Issuers of the press releases are solely responsible for the content of their press releases. PRLog.Org can't be held liable for the contents of the press releases.   Report Abuse


Upcoming Press Releases...


Most Viewed Weekly

Hemispherx BioPharma, Inc hit by shareholder lawsuit - 2861 views

STEC, Inc. hit by shareholder lawsuit - 1394 views

Youbet.com, Inc. board under investigation - 1104 views

25 Smokin’ Figurados Interviewed on DogWatch Cigar Radio - 984 views

The Boeing Company hit by shareholder lawsuit - 948 views


Daily News!

Perfexion, Inc. Listed In Philadelphia Business Journal's Top 25 Web Site Design Agencies

Blue Coat Advances Hybrid Secure Web Gateway to Provide Companies with Continuous Threat Protection

Limerick County Council Closes Black Bridge

Ennis And County Clare Flooding Update (3pm Sunday)

Flooding Report From County Clare - Sun 22 November 1.30pm

Previous   Next

Jul 21, 2009 News

Jul 2009 News

Are you a Journalist?

For Businesses ...

Tutorial on Free Marketing


November 2009
Su Sa Fr Th We Tu Mo
22 21 20 19 18 17 16
15 14 13 12 11 10 9
8 7 6 5 4 3 2
1
October 2009
31 30 29 28 27 26



  1. SiteMap
  2. Contact PR Log
  3. Privacy Policy
  4. Terms of Use
  5. Copyright Notice