oss-sec mailing list archives
Re: Re: Possible CVE request: subversion MD5 collision authentication leak
From: Michael Samuel <mik () miknet net>
Date: Tue, 5 Aug 2014 14:38:05 +1000
On 5 August 2014 08:32, Ben Reser <ben () reser org> wrote:
I think your understanding of the current state of MD5 collision attacks is out of date. Chosen prefix attacks are possible. See: http://www.win.tue.nl/hashclash/ChosenPrefixCollisions/ The MD5 hash is created off the data in the following format: <$URL> $REALM An attacker trying to take advantage of this only needs the $URL portion to match their server. The $REALM can then be whatever data is required to make the MD5 hash match the system they are trying to attack.
Just to clarify - does the attacker have control of both $REALM parameters? A chosen prefix collision still requires the attacker provide both inputs (or at-least the suffix to both inputs). Regards, Michael
Current thread:
- Possible CVE request: subversion MD5 collision authentication leak Marcus Meissner (Aug 01)
- Re: Possible CVE request: subversion MD5 collision authentication leak Ben Reser (Aug 01)
- Re: Re: Possible CVE request: subversion MD5 collision authentication leak Tomas Hoger (Aug 04)
- Re: Re: Possible CVE request: subversion MD5 collision authentication leak Ben Reser (Aug 04)
- Re: Re: Possible CVE request: subversion MD5 collision authentication leak Michael Samuel (Aug 04)
- Re: Re: Possible CVE request: subversion MD5 collision authentication leak Tomas Hoger (Aug 04)
- Re: Possible CVE request: subversion MD5 collision authentication leak Ben Reser (Aug 01)
- <Possible follow-ups>
- Re: Re: Possible CVE request: subversion MD5 collision authentication leak Ben Reser (Aug 05)
