The Beast.....

....is a new toolkit used to exploit a flaw in TLS 1.0.  From what I garner from brief research, it allows someone to decrypt SSL 3.0 / TLS 1.0 transmissions to plaintext without having to insert oneself into the stream; man-in-the-middle attacks.  It is a flaw that was addressed in versions 1.1 and 1.2 of TLS.  However, as standards do, these new revisions have not caught on and leave millions of "secure" transactions a day open to possible exploitation.  Read more in depth analysis in this article at the Register: http://www.theregister.co.uk/2011/09/19/beast_exploits_paypal_ssl/

Comments

Popular Posts