Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Saturday, September 30, 2017

Session tickets in TLS and possible security flaws

Here is an interesting post about session tickets in TLS 1.2 and possible security flaws. The author describes how session resumption works in TLS 1.2, and then discuss three possible flaws in this mechanism. He also mentions how the issues are going to be addressed in TLS 1.3

Enjoy!

WE NEED TO TALK ABOUT SESSION TICKETS

Thursday, September 14, 2017

Diffie-Hellman key exchange in Java

Diffie-Hellman key exchange is a method allows two parties that have no prior knowledge of each other to exchange a shared secret over a public (insecure) channel. This shared secret can then be used to derive a key for a symmetric cipher like AES (from high-level prospective, that's what happens when establishing a TLS connection).

Java supports Diffie-Hellman scheme via KeyAgreement class. Here is an example how Diffie-Hellman key exchange can be implemented with Java.

Wednesday, August 9, 2017

Starting TLS 1.3 server with OpenSSL

At the moment TLSv13 specification is still a draft. But OpenSSL already supports TLSv13. According to this blog post, OpenSSL git master branch contains our development TLS 1.3 code which can be used for testing purposes.

Here are steps how to build OpenSSL with TLS 1.3, and run a local server for testing.

Tuesday, January 17, 2017

Fuzzing GUI applications: AbiWord

It's relatively easy to run fuzzing for a headless application. A headless application doesn't have any GUI, and can be simply run in a terminal. You can use your favorite fuzzer, and feed fuzzed data to the application. Normally, a headless application just processes data, and then quits or crashes right away. But it may be a little different if you are trying to run fuzzing for an application with GUI. This blog post explains how to run fuzzing for AbiWord - an open source text editor.

Read more about Fuzzing GUI applications

Sunday, January 15, 2017

Quick fuzzing of MessagePack

MessagePack is a serialization protocol. It has an implementation on C/C++. Let's check if it has any memory corruption issues. We'll use American Fuzzy Lop and AddressSanitizer for it.

More about MessagePack fuzzing

Tuesday, November 29, 2016

Fuzzing Python marshal protocol

Python's marshal module provides a serialization protocol for Python objects. It provides functionality for writing/reading Python objects in a binary format. This module is used by other Python components, for example, in .pyc files (pseudo-compiled Python code). But Python also has public API to access this serialization protocol.

Wednesday, August 31, 2016

How to implement DNS tunneling in Java

What can you do if a firewall blocks all usual TCP/UDP connections to the Internet? There is one way to establish such a connection if the firewall allows recursive DNS requests to external DNS servers. It's called "DNS tunneling". The article explains how DNS tunneling works, and gives an idea how it can be implemented in pure Java.

Friday, August 19, 2016

Oracle JRE and JDK Cryptographic Roadmap

“Oracle JRE and JDK Cryptographic Roadmap” contains plans for disabling/enabling cryptographic algorithms which are supported in Oracle’s JRE and JDK. This roadmap has been recently published by Java team.


Oracle JRE and JDK Cryptographic Roadmap