Feasibility of attacks against weak SSL/TLS ciphers
Kim van Erkelens
Supervisors: Jeroen van der Ham & Marc Smeets Master System and Network Engineering University of Amsterdam 2 July 2014
Feasibility of attacks against weak SSL/TLS ciphers Kim van - - PowerPoint PPT Presentation
Feasibility of attacks against weak SSL/TLS ciphers Kim van Erkelens Supervisors: Jeroen van der Ham & Marc Smeets Master System and Network Engineering University of Amsterdam 2 July 2014 Introduction Motivation Ciphers like DES and
Kim van Erkelens
Supervisors: Jeroen van der Ham & Marc Smeets Master System and Network Engineering University of Amsterdam 2 July 2014
Introduction
SSL Pulse
2
Introduction
Commercial Security
3
Introduction
What is the feasibility of cracking weak ciphers based on resources required?
used?
resources?
4
Background
5
Background
RDP Transport and Communication TLS TCP Kerberos / NTLM CredSSP TLS TCP User authentication RDP data
Methodology
7
Methodology
8
Methodology
9
Methodology
Methodology
cost of attack drops by a factor 2 every 18 months
Findings
12
Findings
userName: 410064006d0069006e006900730074007200610074006f00... (Administrator) password: 700061007300730077006f00720064000000 (password)
clientInfoPDU
source: fail0verflow
Findings
14
Findings
Feasible
Less feasible
15
Conclusions
16
Conclusions
17
18