Cracked the encryption key of the Superfish Certificate

The security certificate used by the installed add-on to Lenovo computers just broke (Cracked).

We have recently reported that the Superfish software used by Lenovo produces a security certificate to re-sign all the security certificates it receives from HTTPS pages, such as bank pages, virtually allowing access to plain text information to traffic between client and server otherwise it would be encrypted.

Several security experts who looked into the matter revealed that the add-on uses the same RSA key (1024 bits) on all devices, meaning that if someone managed to crack it, they would be able to "read" the encrypted traffic exchanged between a user with a Lenovo computer user and a secure s. That's exactly what he did Robert Graham, Chief Executive Officer of Errata Security.

The researcher used a with Superfish installed by dumping the data generated by the processes into system memory.super-vs

After discovering the encrypted private key of the security certificate used by Superfish, and the certificate itself, it tried to verify that the data is protected by a password.super-01 cracked

Cracking the password turned out to be a bit more difficult than expected, as it required a modified brute-force program. When Graham had to develop a new brute-force software for the needs of this attack.super-02 cracked

Υπέθεσε ότι ο κωδικός πρόσβασης δεν θα ήταν πολύπλοκος, οπότε έδωσε στο πρόγραμμα εντολή αναζήτησης μόνο μεταξύ πεζών γραμμάτων. Σε λιγότερο από 10 , discovered the password which was “komodia.”super-03 cracked

The password decrypts the root certificate and could be used in man-in-the-middle attacks against Lenovo users who have Superfish installed on their system.

super-04 cracked

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).