More than 11 million HTTPS websites at risk from new Drown attack
After the deadly Heartbleed that shocked the world last year, another critical vulnerability is finding ways to create similar concerns. A newly discovered OpenSSL vulnerability enables an outdated protocol , Secure Sockets Layer (SSLv2), to be used in attacks on modern websites.
Readers should understand the severity of this vulnerability, as almost all banks, financial institutions, and other websites that collect personally identifiable information (PII) use HTTPS for secure communication between the user and the web server.
The attack exploiting this vulnerability, called DROWN (Decrypting RSA with Obsolete and Weakened eNcryption), is estimated to be able to take down at least a third of all HTTPS servers. The researchers who discovered the flaw said that at least 11.5 million websites using the HTTPS protocol could be at risk from the Drown attack.
The Drown attack was discovered by academic researchers from the Department of Electrical Engineering, Tel Aviv University, Münster University of Applied Sciences, Horst Görtz Institute for IT security, Ruhr University Bochum, University of Pennsylvania, Hashcat Project, University of Michigan, Two Sigma/OpenSSL, Google/OpenSSL.
The researchers stated: "We are already able to execute the attack against OpenSSL versions vulnerable to CVE-2016-0703 in less than a minute, using a single computer. Even for servers that do not have these specific bugs, the general index of the attack, which works against any SSLv2 server, can be carried out in less than 8 hours, at a total cost of $440."
As of today, some of the top websites listed on Alexa are vulnerable to Drown-based man-in-the-middle attacks, including Yahoo, Sina, and Alibaba. Even India's first state-owned bank, Bank of India, is vulnerable to CVE-2016-0703 (MITM attack), which allows potential hackers to decrypt recorded traffic and steal data.
The researchers said that outdated Microsoft Internet Information Services (IIS) versions 7 and earlier are vulnerable, and versions of Network Security Services (NSS), a common cryptographic library built into many server products, prior to version 3.13 in 2012, are also open to attack.
You can find out if your site is vulnerable by using the DROWN attack test site.
In any case, if you use OpenSSL for security, now is the time to upgrade to 1.0.2g. OpenSSL 1.0.1 users should also upgrade to the 1.0.1s version.

