data:image/s3,"s3://crabby-images/1fd73/1fd7329dff1a6f6ee9f852d2675ebac9508ccb3c" alt=""
Vulnerabilities in SSL & TLS :- Logjam
10 Jan 2022, 9 a.m.
9 Feb 2022, 7:16 p.m.
01:12 minutes
data:image/s3,"s3://crabby-images/6b487/6b48724b04d97f117cab9207434b19ca775224d3" alt=""
In this article we will look at the SSL Logjam vulnerability. This is a person-in-the-middle attack, similar to FREAK, that exposes Export Grade cipher suites. This time, Diffie-Hellman is used instead of RSA.
Main Points
- For this attack to work, the attacker must use a different exploit to become a person-in-the-middle and inject content into the network traffic stream.
- Very similar to FREAK except this time, Diffie-Hellman is used instead of RSA.
- Diffie-Hellman key exchange is a popular cryptographic algorithm that allows Internet protocols to agree on a shared key and negotiate a secure connection. It is essential to many protocols, including HTTPS, SSH, IPsec, SMTPS, and those that rely on TLS.
- The Logjam vulnerability allows a person-in-the-middle attacker to downgrade vulnerable TLS connections to 512-bit export-grade cryptography.
Quick Reference
Description
The SSL Logjam vulnerability allows attackers within person-in-the-middle context to exposes Export Grade cipher suites to downgrade TLS connections.
Name
Logjam
CVE Number
Closest thing to an official CVE number is CVE-2015-4000.
Type of Vulnerability
Method for attacking Die-Hellman (DH) key exchange
Affected
The TLS protocol 1.2 and earlier when a DHE_EXPORT cipher suite is enabled.
Remediation
Disable support for export cipher suites and use a 2048-bit Diffie-Hellman group.