HomeSecurityPHP & Python fail to detect revoked TLS certificates

PHP & Python fail to detect revoked TLS certificates

A simple experiment conducted by security firm Sucuri reveals that four years after the release of a groundbreaking study on the use of SSL/TLS in non-browser applications, some programming languages ​​still fail to validate these certificates.

TLS

Developers today rely on various third-party APIs, providing additional functionality to applications and websites. For example, they use APIs that allow transactions or the use of live chat applications on their sites, while to implement secure connections to the servers of each API, they use the HTTPS and TLS protocols.

When implemented correctly, the TLS protocol provides encryption and authentication. An application that does not properly validate the TLS certificate can allow attackers to intercept users' passwords or payment card details, and more generally any information sent between the two servers.

Back in 2012, a team of scientists led by University of Texas professor Martin Georgiev revealed that various API clients written in PHP, Python, or Java were failing to adequately verify certificates, largely because the languages ​​in question did not include the appropriate tools to do so.

The research work demonstrated that simple MITM attacks can be easily carried out against API infrastructures, leading to successful interception of HTTPS traffic.

[su_button url=”https://www.secnews.gr/100078/%ce%bd%ce%ad%ce%b1-sloth-%ce%b5%cf%80%ce%af%ce%b8%ce%b5%cf%83%ce%b7-%ce%bc%ce%b5%ce%b9%cf%8e%ce%bd%ce%b5%ce%b9-%cf%84%ce%b7%ce%bd-%ce%b1%cf%83%cf%86%ce%ac%ce%bb%ce%b5%ce%b9%ce%b1-%cf%84%cf%89%ce%bd-tl/” target=”blank” style=”glass6″ wide=”yes” center=”yes”]]Read more: New SLOTH attack reduces the security of TLS and SSH protocols[/su_button]

Revisiting this research four years later, security experts at Sucuri created a series of test scripts, in PHP, Python, and Go, that connected to a list of known vulnerable HTTPS servers, and recorded their results to identify potential problems.

The results, illustrated below, show that even newer versions of these programming languages ​​have problems determining the status of an SSL/TLS certificate but terminating connections if they are deemed insecure.

“PHP, Python, and Google Go do not perform revocation checks by default. If the certificate has been compromised and revoked by the owner, you will never know,” says Peter Kankowski of Sukuri.

a

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS