Update Protection against SSL Certificate Forgery via MD5 Collision Attacks
| Check Point Reference: | CPAI-2009-001 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | Description of SSL Certificate Forgery Attack Microsoft Security Advisory (961509) Mozilla Security Blog |
|
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? Users of Web browsers | ||
| Vulnerability Description A new attack affecting digital certificates using the MD5 hash function has been discovered by a group of security researchers. The researchers have identified vulnerability in the Internet Public Key Infrastructure (PKI) used to issue digital certificates for secure website. The attack takes advantage of a weakness in the MD5 cryptographic hash function that allows the construction of different messages with the same MD5 hash, known as an MD5 "collision". The researchers were able to successfully create a rogue Certification Authority (CA) certificate trusted by all common web browsers. This certificate can be used to impersonate any website on the Internet, including banking and e-commerce sites secured using the HTTPS protocol. |
||
|
Vulnerability Details With a rogue CA certificate, certificate validation performed by browsers can be subverted and malicious attackers might be able to monitor or tamper with data sent to secure websites. Attackers would be able to perform man-in-the-middle attacks and execute practically undetectable phishing attacks against such sites, tricking users into disclosing sensitive information such as social security numbers, credit card numbers and account usernames and passwords. |
Protection Overview
By enabling this protection, SmartDefense will be able to detect and block SSL connection attempts to Web sites whose certificate may have been forged using the recently discovered collision attack.
In order for the protection to be activated, update your VPN-1 product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.