PRTODAY / NewswireToday Free press release distribution service network

Agency / Source: Derek Kol Public Relations

This article was published free of charge. Only PREMIUM Articles are (Google AdSense™) 3rd party Ads-Free!

Researchers Uncover Serious Flaw in Handling of Extended Validation SSL by Popular Browsers - Leading security experts reveal how users of EV SSL-protected websites are at risk to silent Man-In-The-Middle attacks
Researchers Uncover Serious Flaw in Handling of Extended Validation SSL by Popular Browsers

 

NewswireToday - /newswire/ - New York, NY, United States, 07/21/2009 - Leading security experts reveal how users of EV SSL-protected websites are at risk to silent Man-In-The-Middle attacks.

   
 


Rank or share this free Newswire Press Release Distribution content. Join the network! Learn How!


Your Banner Ad Here instead - Showing along with ALL Articles covering Fraud/Identity Theft/Piracy Announcements

Replace these Affiliate Programs at ANYTIME! Your banner here within the next hour.


 

Intrepidus Group, a leading provider of information security services and software, today announced research that shows new short comings in browser designs that allow an attacker to silently “Man-In-The-Middle” (MITM) Extended Validation (EV) SSL-protected websites. Users of sites that appear to be secure through the “glow” of their green badge, have been found to be at risk of malicious attacks.

Research conducted by Mike Zusman, principal consultant at Intrepidus Group, and independent security researcher Alex Sotirov shows that a common web browser design flaw can be exploited to compromise SSL encrypted data, even when the user sees the green badge of EV SSL. The researchers have devised a new attack, called SSL Rebinding, which exploits this flaw to sniff sensitive data as it leaves the browser. Zusman and Sotirov have also demonstrated that the same flaw can be leveraged to launch browser cache poisoning attacks against EV SSL protected websites. Both attacks can cause significant exposure and silently expose “encrypted” sessions protected by an EV SSL certificate.

• SSL Rebinding is an attack against an SSL involving a rogue MITM server which uses a combination of SSL certificates to manipulate client behavior and bypass security mechanisms.

• EV Cache Poisoning is a persistent attack, where cached content of an EV SSL protected web site can be poisoned without the victim consciously browsing the site.

“Verifying the “green glow” of EV SSL in the browser has often been pitched as the silver bullet to thwarting phishing attacks,” said Rohyt Belani, CEO of Intrepidus Group. “Our research shows that the green glow can be misleading and provide a false sense of security. Employees and customers should be provided a holistic perspective on phishing to best train them to be resilient to this ever-growing threat.”

Zusman and Sotirov will present the details of their research findings during the Back Hat USA 2009 Briefings & Training conference. Intrepidus Group has also enhanced its PhishMe solution to empower individuals to identify these attacks and protect themselves from cybercrime exposure.

Black Hat USA 2009 Briefings & Training Presentation
Mike Zusman and Alexander Sotirov will be sharing details of this new research on EV SSL Attacks during the Back Hat USA 2009 Briefings & Training conference, at Caesar’s Palace in Las Vegas, Nevada. Their session will be held on “Day 2,” July 30, 2009 in the “//random” track from 3:15 to 4:30 pm.

About PhishMe
PhishMe is a software-as-a-service (SaaS) solution designed to help prevent damage, theft and loss caused by targeted (spear) phishing attacks. PhishMe facilitates and automates the execution of mock phishing exercises against employees, provides clear and accurate reporting on user behavior, and most importantly provides instant, targeted employee training. This method of delivering training materials is recommended by SANS and found to be most effective by researchers at Carnegie Mellon University.

About Intrepidus
Intrepidus Group (intrepidusgroup.com) is a leading provider of information security consulting services and software solutions. With offices in New York City and the Washington DC metro area, the company offers innovative solutions to help clients build employee awareness around common information security issues. Intrepidus Group’s consultants also conduct hands-on assessments of critical applications, networks and products to uncover vulnerabilities, and provide strategic and tactical recommendations to address identified issues. Intrepidus Group One Penn Plaza, Suite 6180, New York, New York 10119

PhishMe.com is a registered trademark of Intrepidus Group. All other product and company names herein are or may be trademarks of their respective owners.

 
 


Rank or share this free Newswire Press Release Distribution content. Join the network! Learn How!


Your Banner Ad Here instead - Showing along with ALL Articles covering Fraud/Identity Theft/Piracy Announcements

Replace these Affiliate Programs at ANYTIME! Your banner here within the next hour.


 

Agency / Source: Derek Kol Public Relations

 
 

Availability: All Regions (Including Int'l)

 

Traffic Booster: [/] Quick Newswire Today Visibility Checker

 

Distribution / Indexing: [+]

 
 
# # #
 
 
  Your Banner Ad showing on ALL
Fraud/Identity Theft/Piracy articles,
CATCH Visitors via Your Competitors Announcements!


Researchers Uncover Serious Flaw in Handling of Extended Validation SSL by Popular Browsers

Non-featured company website links are shown on a random basis
It is OK to republish and/or LINK any newswire for any legitimate media purpose as long as you name Newswire Today and LINK as the source.
 
  For more information, please visit:
Links are available on a random basis for non premium members
|
Contact: Derek Kol 
818-681-9400 derek[.]derekkol.com
 
Newswire Today - PRZOOM / PRTODAY disclaims any content contained in this article. If you need/wish to contact the company who published the current release, you will need to contact them - NOT us. Issuers of articles are solely responsible for the accuracy of their content. Our complete disclaimer appears here.
IMPORTANT INFORMATION: Issuance, publication or distribution of this press release in certain jurisdictions could be subject to restrictions. The recipient of this press release is responsible for using this press release and the information herein in accordance with the applicable rules and regulations in the particular jurisdiction. This press release does not constitute an offer or an offering to acquire or subscribe for any Derek Kol Public Relations securities in any jurisdiction including any other companies listed or named in this release.

Fraud/Identity Theft/Piracy via RSS
AddThis press release: Researchers Uncover Serious Flaw in Handling of Extended Validation SSL by Popular BrowsersAdd Fraud/Identity Theft/Piracy News to My MSNAdd Fraud/Identity Theft/Piracy News to My Yahoo!Add NewswireToday Fraud/Identity Theft/Piracy Press Release Headline News to Your Google homepage or Google ReaderAdd NewswireToday - PRZOOM Headline News to FeedBurner Twitter /NewswireToday

This article was published free of charge. Only PREMIUM Articles are (Google AdSense™) 3rd party Ads-Free!


Read Latest Articles From Derek Kol Public Relations / Company Profile



N-able Technologies and NTRglobal Deliver Secure Cloud-Based Remote Connectivity to N-able Partners
Nexsan Flexible Storage Platform Selected by Brigham Young University Computer Science Department
Connectria Hosting Achieves 'Off the Chart' Operational Efficiency with Cloud-Based Storage Solution
Nexsan Recognized in CRN Magazine's Data Center 100 for Data Center Efficiency, Performance and ROI
Asigra Named Best Channel Vendor by Business Solutions Magazine
Asigra Answers Most Frequently Asked Questions About Cloud Backup in New Guide for SMBs and Enterprises
Atlantis Computing Expands VDI Solution Partner Program
TechnoBind and Nexsan Team in Indian Subcontinent to Deliver Easy, Efficient, Enterprise-Class Stora
Asigra Powers NTT America Cloud Backup for Medium and Large Enterprises
ESG Survey Reveals Two Out of Three Enterprises Use SharePoint as Business Critical Application
Storage Switzerland Review Identifies Gridstore 2.0 As The Easiest Scale-Out NAS Implementation
Experts Cite Importance of Data De-Identification in Overall Risk Assessment Framework
Nexsan E60 and E18 High Performance Storage Systems Awarded Symantec Backup Exec Certification
Liberty University Offloads 69 Percent Of Unstructured SharePoint Content with Metalogix StoragePoint
New GD400 Rugged Handheld Computer Narrows Divide Between SmartPhones and Full-Sized Computers

Reserve This Permanent SPACE

Your LOGO permanently HERE on Newswire Today most visited Page start at $295 per month

 
Sponsored Links


Visit  Pickerel Lake Recovery Treatment Center

Visit  BizJobs.com










 
  ©2012 Newswire Today — Limelon Advertising, Co.
Home | About | Advertise | Contact | Investors | Sitemap | FRANCAIS
newswire, PR free press releases distribution magazines engine news alert newsroom press room breaking news public relations articles company news alerts blogsIt younews.me newswiredistribution ezine younews.asia bizentrepreneur biznewstoday digital business report market search pr firms agencies reports distri- bution today investor relation successful internet entrepreneur free newswire distribution prtoday.com freenewswiredistribution asianewstoday bizwiretoday USA pr UK today
 
PRTODAY & NewswireTODAY are NOT affiliated with USA TODAY (usatoday.com)