Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    1998 Vintage Cryptography Vulnerability Known as ROBOT Re-Emerges

    Written by

    Sean Michael Kerner
    Published December 13, 2017
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Security researchers disclosed a vulnerability dubbed ROBOT on Dec. 12 that is based on an encryption risk that was first disclosed in 1998. Multiple hardware vendors and well-known public websites were potentially at risk from the flaw, which has now been patched.

      The Return Of Bleichenbacher’s Oracle Threat (ROBOT) was reported by security researchers Hanno Böck, Juraj Somorovsky and Craig Young.

      “Many web hosts are still vulnerable to one of the oldest attacks against RSA in TLS,” the researcher abstract stated. “We show that Bleichenbacher’s RSA vulnerability from 1998 is still very prevalent in the Internet and affects almost a third of the top 100 domains in the Alexa Top 1 Million list, among them Facebook and Paypal.”

      “In 1998, Daniel Bleichenbacher discovered that the error messages given by SSL servers for errors in the PKCS #1 1.5 padding allowed an adaptive-chosen ciphertext attack,” an FAQ on the ROBOT attack states. “This attack fully breaks the confidentiality of TLS when used with RSA encryption.”

      The researchers discovered that the same attack with slight varation is still possible against modern websites. There are multiple impacted vendors that include SSL/TLS in their products including Cisco, F5 and Citrix. Craig Young, security researcher at Tripwire and a co-author of the ROBOT research said that he was not terribly surprised to find that there were still SSL/TLS implementations that were vulnerable to the Bleichenbacher attack. What was surprising to him was that the researchers were able to find reliable attacks on equipment serving so many prominent web sites.

      “It has been pretty well-known in the crypto community for some time that the Bleichenbacher countermeasures are difficult to get right,” Young told eWEEK. “One of the driving forces behind this research was to demonstrate conclusively why RSA encryption based key exchange modes should be deprecated from use.”

      While the ROBOT attack is possible, it’s not necessarily easy. The researchers have not yet publicly released any code for organizations to attempt to exploit the vulnerability. Young said that the researchers that conducted the ROBOT research have built their own tool which can decrypt and sign, using the private keys of vulnerable servers.  

      “We are also aware that other researchers have designed tools for exploiting Bleichenbacher including published algorithms as referenced in our paper,” Young said. “After sufficient time has passed for patch deployment, our attack code will be released for others to study and build upon.”

      Tod Beardsley, director of research at security firm Rapid7 commented that he was surprised at the number of sites and vendors that were at risk from the flaw.

      “We already have much better key exchange and padding functions widely available today and there is no good reason to keep these around,” Beardsley told eWEEK. “But, I suppose that shouldn’t be too surprising—the internet is pretty sticky when it comes to hanging on to old technologies.”

      What Should Users Do?

      There is a simple test available that can help organizations to determine if they are at risk from ROBOT. Additionally multiple vendors have issued patches to help mitigate the risk. A full list of vendor patches is available here.

      Another option to help mitigate the risk, is the use of the TLS 1.3 protocol which is expected to become a formal standard in 2018. Young noted that the decision was made early on in the standards process that TLS 1.3 will not use the vulnerable static RSA key exchanges that make the ROBOT attack possible.

      Beardsley commented that the best thing IT administrators can do today is to see if they’re still providing the affected RSA cyphers and disable those for any service where cryptographic security is desired.

      “Also, IT administrators should make it a habit to scan their own environment today, and going forward, in order to catch new TLS endpoints that offer these deprecated RSA ciphers,” Beardsley said. “This should be part and parcel of any normal, routine vulnerability scanning that mature security organizations already perform.

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×