Telegram Group & Telegram Channel
Forwarded from 科技圈的日常 (Jimmy Tian)
一份来自于奇虎 360 核心安全团队于今日披露的论文显示:

Shadowsocks 的 steam 加密存在漏洞,导致数据包头部可被修改。

攻击者可以利用修改过后的数据包进行「重定向」,从而进行 MITM 攻击。

目前受影响的包括:shadowsocks-py, shadowsocoks-go, shadowsocoks-nodejs

研究者推荐仅使用 shadowsocks-libev 配合以下三种加密算法:

aes-gcm chacha-ietf-poly1305 xchacha20-ietf-poly1305 (备注:SSR 不支持任意一种)

POC 与论文地址:https://github.com/edwardz246003/shadowsocks

部分原文摘抄:

A passive attacker can easily decrypt all the encrypted shadowsocks packet using our redirect attack. Even more, a man-in-the-middle attacker can modify traffic in real time like there is no encryption at all.

What surprised us was that only shadowsockslibev support AEAD cipher. All other official implementation only support steam cipher. This means that the data integrity and authenticity of most SS users is not guaranteed from a Mitm attacker.



tg-me.com/Safecraze/22
Create:
Last Update:

一份来自于奇虎 360 核心安全团队于今日披露的论文显示:

Shadowsocks 的 steam 加密存在漏洞,导致数据包头部可被修改。

攻击者可以利用修改过后的数据包进行「重定向」,从而进行 MITM 攻击。

目前受影响的包括:shadowsocks-py, shadowsocoks-go, shadowsocoks-nodejs

研究者推荐仅使用 shadowsocks-libev 配合以下三种加密算法:

aes-gcm chacha-ietf-poly1305 xchacha20-ietf-poly1305 (备注:SSR 不支持任意一种)

POC 与论文地址:https://github.com/edwardz246003/shadowsocks

部分原文摘抄:

A passive attacker can easily decrypt all the encrypted shadowsocks packet using our redirect attack. Even more, a man-in-the-middle attacker can modify traffic in real time like there is no encryption at all.

What surprised us was that only shadowsockslibev support AEAD cipher. All other official implementation only support steam cipher. This means that the data integrity and authenticity of most SS users is not guaranteed from a Mitm attacker.

BY 信息安全狂热者




Share with your friend now:
tg-me.com/Safecraze/22

View MORE
Open in Telegram


信息安全狂热者 Telegram | DID YOU KNOW?

Date: |

Dump Scam in Leaked Telegram Chat

A leaked Telegram discussion by 50 so-called crypto influencers has exposed the extraordinary steps they take in order to profit on the back off unsuspecting defi investors. According to a leaked screenshot of the chat, an elaborate plan to defraud defi investors using the worthless “$Few” tokens had been hatched. $Few tokens would be airdropped to some of the influencers who in turn promoted these to unsuspecting followers on Twitter.

Spiking bond yields driving sharp losses in tech stocks

A spike in interest rates since the start of the year has accelerated a rotation out of high-growth technology stocks and into value stocks poised to benefit from a reopening of the economy. The Nasdaq has fallen more than 10% over the past month as the Dow has soared to record highs, with a spike in the 10-year US Treasury yield acting as the main catalyst. It recently surged to a cycle high of more than 1.60% after starting the year below 1%. But according to Jim Paulsen, the Leuthold Group's chief investment strategist, rising interest rates do not represent a long-term threat to the stock market. Paulsen expects the 10-year yield to cross 2% by the end of the year. A spike in interest rates and its impact on the stock market depends on the economic backdrop, according to Paulsen. Rising interest rates amid a strengthening economy "may prove no challenge at all for stocks," Paulsen said.

信息安全狂热者 from us


Telegram 信息安全狂热者
FROM USA