Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Advisories

August 11th, 2009, 11:00 GMT · By Catalin Cimpanu

Man-in-the-Middle HTTPS Attack Weak Point in Major Browsers

SHARE:

Adjust text size:


Major Browsers Logos
Enlarge picture
In a research project carried at Microsoft, developers broke numerous secure HTTPS connections using a man-in-the-middle attack with the aid of a specially configured proxy. Based on the results of this research, security experts from SecurityFocus revealed several vulnerabilities found in all major modern browsers.

The SecurityFocus advisory initially targeted Mozilla (which subsequently released a security update), but it was recently updated to reflect all major browsers like: Opera, Internet Explorer, Safari and Chrome.

Using Pretty-Bad-Proxy (PBP), three developers from Microsoft and a teaching assistant from Purdue's Computer Science department revealed several loopholes in browser behavior regarding HTTPS connections. They were able to inject HTML and scripting language inside a secure page, which lead to a breach inside the HTTPS connection without ever breaking the cryptographic scheme.

This way, they were able to steal secure data from the connection, fake a secure server, fake a secure page and impersonate an authenticated user in a server-client conversation. Regarding this issue, the developers said in their statement that “These vulnerabilities reflect the neglects in the design of modern browsers. […] Thus further (and more rigorous) evaluations of the HTTPS deployments in browsers appear to be necessary.”

According to the researchers, all major web browser companies were informed about this issue and have planned to patch their browsers. Until now, only Firefox was updated in June. Meanwhile, the rest of the browsers continue to be vulnerable against man-in-the-middle type of attacks in HTTPS connections.

In principle, the major flaw that cripples all browsers is that they are executing all error messages inside the secure environment of the page being called, so all requests and data can be sniffed and modified by PBP. If cookies are enabled and involved in the authentication process, credentials and account info can be intercepted and stolen.

The complete report from SecurityFocus can be found here and the Microsoft research here.

A standard PBP attack
Enlarge picture
Embedding scripts in 4xx and 5xx error mesages
Enlarge picture
An attack using 3xx redirection messages
Enlarge picture
PBP fakes a secure HTTPS page
Enlarge picture


TELL US WHAT YOU THINK:

3,827 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Security and Privacy Gurus Plead to Google for Default HTTPS

0-Day Exploit for Critical Firefox Vulnerability Released

Mozilla Patches Recently Disclosed SSL Vulnerabilities

Firefox 3.5 and IE8 Abused to Spy Inside Intranets

Researcher Spoofs the Entire Web with Wildcard SSL Certificate

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM