Home » Headline, Security

MD5 Vulnerability

3 January 2009 995 views 2 Comments Print This Post Print This Post Email This Article Email This Article
by John Tracy

MD5 ExploitAlthough this is not a direct WordPress vulnerability, it is a severe vulnerability that webmasters should be aware.

A new paper out this week details the exploit of MD5 and Certificate Athorities (CA). What makes this such a scary and threatening attack is the use of MD5 to secure a website identity. Using the HTTPS protocol, web surfers verify the identity of secure sites by checking for the lock icon and the use of HTTPS in the web address.

Using this exploit, an attacker can fake the authenticity of a website by giving the user a genuine certificate.

What can you do to protect the identity of your site, and sites you visit?

The first thing is to make sure the CA is using SHA-2 instead of MD5. Next is to make sure the CA of the sites you visit do the same. Sure, this isn’t the best advise, and not everyone will take it, but at the moment, it is the only way to be sure you are safe.

Please read through the paper here. It is quite detailed, and will let you know exactly how the exploit was achieved.

1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...

This website uses IntenseDebate comments, but they are not currently loaded because either your browser doesn't support JavaScript, or they didn't load fast enough.

2 Comments »

  • 导航网 said:

    博主的文章不错。是自己写的吗?我要转载一下,请问你是原作者吗?

  • John Tracy (author) said:

    Yes I am the original author of this publishing, the paper I linked to, however, is the written by those mentioned on their site.

Leave your response!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.