Cracked the encryption key of the Superfish Certificate

The security certificate used by the Superfish add-on installed on its computers just broke (Cracked).

Πρόσφατα, αναφέραμε ότι το λογισμικό Superfish που χρησιμοποιείται από τη Lenovo παράγει ένα πιστοποιητικό ασφαλείας για να υπογράψει εκ νέου όλα τα πιστοποιητικά ασφαλείας που λαμβάνει από σελίδες HTTPS, όπως σελίδες τραπεζών, επιτρέποντας ουσιαστικά την σε πληροφορίες απλού κειμένου στην κίνηση μεταξύ and a server that would otherwise be encrypted.

Many security experts who have examined the subject have discovered that the add-on uses the same RSA key (1024 bits) on all devices, which means that if someone manages to break it, they will be able to "read" the encrypted traffic exchanged between a user with a Lenovo user computer and a secure service. This is exactly what he did Robert Graham, Chief Executive Officer of Errata Security.

The researcher used a system with Superfish installed by dumping the data generated by processes into the system memory.super-vs

After discovering the encrypted private key of the security certificate used by Superfish, and the certificate itself, it tried to verify that the protected with a password.super-01 cracked

Cracking the password turned out to be a bit more difficult than expected since it required a modified brute-force program. When Graham had to develop a new brute-force software for her needs s.super-02 cracked

He assumed that the password would not be complicated, so he gave the program a search command only between lowercase letters. In less than 10 seconds, he discovered the password that was "komodia."super-03 cracked

The password decrypts the root certificate and could be used in man-in-the-middle attacks against Lenovo users who have Superfish installed on their system.

super-04 cracked

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).