Submit Your Article Forum Rules

Results 1 to 6 of 6

Thread: Beast

  1. #1
    Senior Member alphaomega's Avatar
    Join Date
    Apr 2004
    Location
    Sunshine Coast, Australia
    Posts
    601

    Beast

    I am sure some of you are aware of the new exploit of SSL connection. We have had secure connection and took it for granted. BEAST can crack the cookie and enter your account long after you closed your browser. For those who are selling online this is a very important issue and steps should be taken asap. Read deetailed report from TechRepublic article on the following link.
    http://www.itscolumn.com/2011/10/how...curity+Column)

  2. #2
    Junior Member
    Join Date
    Aug 2011
    Posts
    15
    OK, so I understand what it is saying, but at the same time I don't get it. Is it saying that this BEAST can place fake orders? Or is it saying that it can rip credit card information?

  3. #3
    WebProWorld MVP deepsand's Avatar
    Join Date
    May 2004
    Location
    State College, PA
    Posts
    16,459
    What it means is that encryption using TLS (Transport Layer Security) 1.0 or below is no longer secure. Thus, any data so encrypted are vulnerable.

  4. #4
    Senior Member
    Join Date
    Dec 2010
    Posts
    118
    CC info is not stored in a cookie. Or better not be. But yes, somebody could use the info to place orders on your account, if the site has one of those "use previous information" functions. Then they have it shipped to their location.

  5. #5
    WebProWorld MVP deepsand's Avatar
    Join Date
    May 2004
    Location
    State College, PA
    Posts
    16,459
    Quote Originally Posted by DonOmite View Post
    Then they have it shipped to their location.
    Only if merchant does not verify CVC and use strict AVS.

  6. #6
    Junior Member
    Join Date
    Feb 2012
    Posts
    12
    BEAST was sensationalised by the press as most people don't use TLS1.0.

    SSL has been broken for a long time, but BEAST didn't really do anything new... It was just more graceful.
    I like to compare it with FireSheep. It wasn't a new idea, just easy to adopt and sell for a profit. It made a, somewhat esoteric, hacking principle into something any script kiddie could do.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •