About RSS
Search for: in 

Windows Watch - an XP & Vista blog

R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

Critical flaws found in IPsec protocols

VPNs vulnerable to hackers, warns NISCC

Iain Thomson, vnunet.com 13 May 2005
ADVERTISEMENT

Flawed cryptography is leaving people using IPsec security protocols vulnerable to hacking, according to the UK's National Infrastructure Security Coordination Centre (NISCC).

The organisation has released an advisory about the discovery of three key flaws in the Encapsulating Security Payload (ESP) that provides base-level encryption of data, typically travelling though virtual private networks.

"An attacker could modify sections of the IPsec packet, causing either the cleartext inner packet to be redirected or a network host to generate an error message," warned NISCC.

"In the latter case, these errors are relayed via the Internet Control Message Protocol. Because of the Protocol's design, these messages directly reveal segments of the header and payload of the inner datagram in cleartext.

"The attacks have been implemented and demonstrated to work under realistic conditions."

The organisation rates the flaws as 'highly critical' and added that the Authentication Header protocols that guarantee the authenticity of data packets are also vulnerable.

The advisory provides three ways to work around the problem, including reconfiguring the ESP system and using Authentication Header and ESP simultaneously to defeat eavesdroppers.

See also:

Market set to reach $5.8bn in 2009  18 Mar 2005
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Reading, Berkshire, United Kingdom | EDS
System Integrator - Applications Hosting Location - Reading Job Description: A skilled System Integrator to integrate Microsoft based applications to support business requirements. The Candidate will possess specific experience of enterprise systems, component validation and ... more >
London, United Kingdom | Feltham City Learning Centre
ICT Systems Administrator - Feltham City Learning Centre - £23,097 - £24,528 A full time ICT Systems Administrator to work in the Feltham City Learning Centre. This role requires a broad range of ICT skills ... more >
London, United Kingdom | Royal Borough of Kensington and Chelsea
Web Content Manager - c.£40,000 plus bonus - London   As one of the country's best-performing councils, we're always looking for new ways to improve on excellence. Providing an innovative, high-quality internet site for our ... more >
Canary Wharf, Greater London, United Kingdom | EDS
Position # 398441 Responsibilities - Testing Consultant * Under broad direction, interacts with EDS project teams and clients to gain an understanding of the business environment, technical context, and testing objectives for a project as ... more >
More job opportunities
Join our fight for a fair deal when shopping online
ADVERTISEMENT