Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Is is possible to test for tls racoon? #1728

Open
chrisdlangton opened this issue Sep 16, 2020 · 2 comments
Open

Is is possible to test for tls racoon? #1728

chrisdlangton opened this issue Sep 16, 2020 · 2 comments

Comments

@chrisdlangton
Copy link

A side channel, so maybe not.
Info
https://hackaday.com/2020/09/11/security-this-week-racoons-in-my-tls-bypassing-frontends-and-obscurity/

@drwetter
Copy link
Owner

I haven't found the time to read https://raccoon-attack.com/ completely yet (hello to Paderborn and Bochum at least).

The exceptions might be worth to look into, maybe the reuse of ephemeral and non-ephemeral keys could be detected. But that's only an assumption.

Have you read about a PoC for detection? Wondering how SSLlabs is doing that.

@chrisdlangton
Copy link
Author

I came here looking for such a thing ;)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants