The OpenSSL project has just released the updated versions 1.0.2g and 1.0.1s to address a high-severity security issue. The vulnerability allows DROWN attacks (CVE-2016 – 0800). The attack allows attackers to bypass secure HTTPS connections and steal encrypted information.
DROWN is an abbreviation of “Decrypting RSA using Obsolete and Weakened eNcryption” or “Decrypting RSA using obsolete and weakened encryptions” and was discovered by a team of 15 researchers from various universities of the INFOSEC community.
The principle behind the DROWN attack is based on the presence of both SSLv2 and TLS protocols on the target machines. It is an attack for both protocols, which means it will exploit the vulnerabilities of the SSLv2 implementation against TLS.
The vulnerability originates from the Bleichenbacher attack on RSA, an encryption system used by SSL and also by TLS. Before an encrypted connection exists, the client must choose a random session key that is encrypted via RSA and sent to the server, which then authenticates the client and starts the HTTPS connection.
The Bleichenbacher attack, discovered in the late ’90s. It uses a method to obtain the original RSA key that relies only on a server response “yes” or “no” to the question “is this the RSA session key;”
Researchers behind the DROWN attack discovered new ways to use the Bleichenbacher attack, leveraging the fixes and additions of SSLv2.
The attack works for TLS connections as well, a protocol is considered to be superior to SSL. However, regardless of the differences between them, both protocols use the same RSA session encryption key to establish an HTTPS connection.
Who is at risk?
Only servers that still use SSLv2 and TLS simultaneously are vulnerable to the flaw. Therefore, disabling SSLv2 on your server should be the first thing you do.
Additionally, the researchers warn about a specific server setting that could expose systems to vulnerability, even if the main website uses only TLS.
“You also risk, if the certificate or some key from your site is used elsewhere on a server that does not support SSLv2”, the researchers say.
“Common examples include the SMTP, IMAP protocols, POP mail servers, and also the secondary HTTPS server used for specific web applications.”
We should note that Canonical, in its honor, has already updated the Ubuntu operating system.
