Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE
An attack on CRC-32 integrity checks on encrypted channels using CBC and CFB modes

.pdf file available (english version)

Abstract

A known-plaintext attack against SSH protocol version1.5 is described that allows an attacker to insert arbitrary commands in the stream regardless of the authentication protocol used, the block cipher or the key. The attack is based on weaknesses of the integrity function used (CRC-32) that become exploitable due to the use of CBC and CFB feedback modes.

Related Content