[bestbits] SSLv2 DROWN Attack

Wisdom Donkor wisdom.dk at gmail.com
Mon Mar 7 07:32:07 EST 2016


Dear All,

Network traffic encrypted using an RSA-based SSL certificate may be
decrypted if enough SSLv2 handshake data can be collected. Exploitation of
this vulnerability - referred to as DROWN in public reporting - may allow a
remote attacker to obtain the private key of a server supporting SSLv2.
CERT-GH encourages users and administrators to review the attached advisory
for additional information and mitigation details.

Find attached advisory

Cheers,


*WISDOM DONKOR (S/N Eng.)*
ICANN Fellow / ISOC Member, IGF Member, Diplo Foundation
OGP Working Group Member, Africa OD Working Group Member
E-government / Open Government Data Specialist
National Information Technology Agency (NITA)
Ghana Open Data Initiative (GODI)
Post Office Box CT. 2439, Cantonments, Accra, Ghana
Tel; +233 20 812881
Email: wisdom_dk at hotmail.com
wisdom.donkor at data.gov.gh
wisdom.dk at gmail.com
Skype: wisdom_dk
facebook: facebook at wisdom_dk
Website: www.nita.gov.gh / www.data.gov.gh
www.isoc.gh / www.itag.org.gh
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.igcaucus.org/pipermail/bestbits/attachments/20160307/90ea9d78/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: SSLv2 DROWN Attack_CERT-GH-ADV10102032016.pdf
Type: application/pdf
Size: 242562 bytes
Desc: not available
URL: <http://lists.igcaucus.org/pipermail/bestbits/attachments/20160307/90ea9d78/attachment.pdf>


More information about the Bestbits mailing list