accept no compromises
Showing 1 - 25 of 39 RSS Feed

Files

Cryptanalysis Of INCrypt32 In HID's iCLASS Systems
Posted Feb 7, 2012
Authored by Daewan Han, Dong Hoon Lee, ChangKyun Kim, Chang-Ho Jung, Eun-Gu Jung

The cryptographic algorithm called INCrypt32 is a MAC algorithm to authenticate participants, RFID cards and readers, in HID Global's iCLASS systems. HID's iCLASS cards are widely used contactless smart cards for physical access control. Although INCrypt32 is a heart of the security of HID's iCLASS systems, its security has not been evaluated yet since the specification has not been open to public. In this paper, they reveal the specification of INCrypt32 by reverse engineering an iCLASS card and investigate the security of INCrypt32. As a result, we show that the secret key of size 64 bits can be recovered using only 218 MAC queries if the attacker can request MAC for chosen messages of arbitrary length. If the length of messages is limited to pre-determined values by the authentication protocol, the required number of MAC queries grows to 242 to recover the secret key.

tags | paper, arbitrary, crypto, protocol
MD5 | ee33f7e2da98c62d3b33c6294941bbe8
Baseline Requirements For Publicly-Trusted Certificates 1.0
Posted Dec 17, 2011
Site cabforum.org

This document is version 1.0, as adopted by the CA/Browser Forum on 22 Nov. 2011 with an Effective Date of 1 July 2012. These Baseline Requirements describe an integrated set of technologies, protocols, identity-proofing, lifecycle management, and auditing requirements that are necessary (but not sufficient) for the issuance and management of Publicly-Trusted Certificates; Certificates that are trusted by virtue of the fact that their corresponding Root Certificate is distributed in widely-available application software. The Requirements are not mandatory for Certification Authorities unless and until they become adopted and enforced by relying–party Application Software Suppliers.

tags | paper, root, protocol
MD5 | 63d03aa7d401de867cf392a08b47eb93
On Equivalence Between Zeta And R-Sequence
Posted Dec 13, 2011
Authored by Michal Bucko

This paper covers a conjecture of equivalence between a statement regarding Ξ matrix and Zeta.

tags | paper
MD5 | ffeb0704f3a4f742f8cdc662a27b89a1
On The R-Sequence And Prime Key Set Problem
Posted Dec 13, 2011
Authored by Michal Bucko

This document covers the introduction of the R-sequence, i.e. the sequence of numbers closely related to the distribution of the prime numbers. The paper contains its connection to ζ and Mobius function.

tags | paper
MD5 | 7eb0b52dfcf76b9629a1e7004f39e0ca
TLS/SSL Hardening And Compatibility Report
Posted Sep 30, 2011
Authored by Thierry Zoller | Site g-sec.lu

This report gives general recommendations as to how to configure SSL/TLS in order to provide state of the art authentication and encryption. The options offered by SSL engines grew from the early days since Netscape developed SSL2.0. The introduction of TLS made matters more challenging as servers and clients offer different sets of available options depending on which SSL engine (OpenSSL, NSS, SCHANNEL, etc.) they use. Finding the middle ground has proven difficult especially as the supported protocols and cipher suites are mostly not documented. To make matters more complicated Browsers may not use all functionality offered by the SSL stack, this report will only list functionality used by current Browsers. This report provides an overview of the currently available TLS options across Servers and Clients and allows you to offer support for a wide variety of Browsers an offer "good enough" security.

tags | paper, protocol
MD5 | ea3ba9ca23ddccb36b094184551e503d
Biclique Cryptanalysis Of The Full AES
Posted Aug 19, 2011
Authored by Dmitry Khovratovich, Andrey Bogdanov, Christian Rechberger

Whitepaper called Biclique Cryptanalysis of the Full AES. Since Rijndael was chosen as the Advanced Encryption Standard, improving upon 7-round attacks on the 128-bit key variant or upon 8-round attacks on the 192/256-bit key variants has been one of the most difficult challenges in the cryptanalysis of block ciphers for more than a decade. This paper discusses shortcut attacks on AES.

tags | paper
MD5 | 709a1f2c8b9ff655ca735589dc58c746
Remote Timing Attacks Are Still Practical
Posted May 25, 2011
Authored by Nicola Tuveri, Billy Bob Brumley

This whitepaper describes a timing attack vulnerability in OpenSSL's ladder implementation for curves over binary fields. They use this vulnerability to steal the private key of a TLS server where the server authenticates with ECDSA signatures. Using the timing of the exchanged messages, the messages themselves, and the signatures, they mount a lattice attack that recovers the private key. Finally, they describe and implement an effective countermeasure.

tags | exploit, paper, crypto, vulnerability
MD5 | 4558b899d97a106def3ba064ab5eadfe
Elliptic Curve Cryptography Anomalous Curves
Posted Sep 11, 2010
Authored by Alonso De Jesus Garcia Herrera, Carlos Mario Penagos Hollmann

Whitepaper called Elliptic Curve Cryptography Anomalous Curves. Written in Spanish.

tags | paper
MD5 | 2b639c3df334eaf5d930ef387fb86c6c
Whitepaper Comparing MD5 To Windows LM Hashes
Posted Mar 22, 2010
Authored by Jeremy Langford

This whitepaper is a comparison of the security provider by Window's Local Area Network Manager and Message Digest Five hashes in the application of personal and business computers.

tags | paper, local
MD5 | 8ce3495b25e25aefeec5867bb6f68765
Cryptography - The Magic Of The Asymmetric
Posted Jan 26, 2010
Authored by Keksa

Whitepaper called Cryptography - The Magic Of The Asymmetric. Written in German.

tags | paper
MD5 | 7a1072950ad30ae37a0f62a304949013
SSL Sniffing
Posted Jan 11, 2010
Authored by Aokan | Site knyksl.com

Whitepaper called SSL Sniffing. It discusses the basic use of SSL and what types of attack tools and methodologies exist.

tags | paper
MD5 | ccc23804455e187b044d226ff6feca5a
breaking-rsa.txt
Posted Nov 15, 2007
Authored by Alex Bassas Serramia

Whitepaper titled Breaking RSA: Totient indirect factorization.

tags | paper
MD5 | 05bb3993fce0e3665a7a454a31c6c7a1
Cryptography.pdf
Posted Jul 14, 2005
Authored by Ashish Anand | Site ashishanand2.tripod.com

Whitepaper entitled Application Level Cryptography: Combination Stream And Block Ciphering Using Double Encryption Algorithms.

tags | paper
MD5 | afc7aedcfa978bac8776fd03f43ea6a5
practical-public-key-crypto.pdf
Posted Jul 12, 2005
Authored by pagvac (Adrian Pastor), Petko Petkov, Rabia Barakat

Practical Applications of Public-key Cryptography: Securing Email Communications with PGP. An 11 page tutorial that discusses practical uses of PGP desktop, the commercial version of PGP.

tags | paper
MD5 | 81761434a44e7b3e64b6930079905871
Brief_intro_to_crypt.pdf
Posted Feb 26, 2005
Authored by PAgVac

Brief paper discussing the basics of cryptography and the difference between symmetric and asymmetric cryptography.

tags | paper
MD5 | 1fb7d951e26e627eb3917c88148cf3ea
0501038.pdf
Posted Jan 26, 2005
Authored by D.J. Capelis

White paper discussing the new ASH family of hashing algorithms. They are based off of modifications to the existing SHA-2 family and were designed with two main goals in mind: Providing increased collision resistance and increasing mitigation of security risks post-collision.

tags | paper
MD5 | cfc40a525aab63b7075b6e7b4760d13a
007.pdf
Posted Jan 12, 2005
Authored by Hongjun Wu

White paper discussing the misuse of RC4 in Microsoft Word and Excel, where the initialization vector of RC4 remains the same when an encrypted document gets modified and saved,

tags | paper
MD5 | 4b51c7d51729aa139604ffad57258c26
stripwire-1.1.tar.gz
Posted Dec 7, 2004
Authored by Dan Kaminsky | Site doxpara.com

Stripwire is a tool which demonstrates vulnerabilities in md5 checks described in this paper. Contains a perl script which proves that if md5(x) == md5(y), then md5(x+q) == md5(y+q) (assuming length(x) and length(y) are 0 mod 64, and q is any arbitrary data). This is true because once two blocks converge upon the same hash, the nature of them being different has thereafter been lost.

tags | paper, arbitrary, perl, vulnerability
MD5 | aa5a1a01f2f6e05656fff5d5304c59b2
md5_someday.pdf
Posted Dec 7, 2004
Authored by Dan Kaminsky | Site doxpara.com

Collision vulnerabilities in MD5 Checksums - It is possible to create different executables which have the same md5 hash. The attacks remain limited, for now. The attack allows blocks in the checksumm'd file to be swapped out for other blocks without changing the final hash. This is an excellent vector for malicious developers to get unsafe code past a group of auditors, perhaps to acquire a required third party signature. Alternatively, build tools themselves could be compromised to embed safe versions of dangerous payloads in each build. A tool to demonstrate these vulnerabilities is available here.

tags | paper, vulnerability
MD5 | 5e1605409d78efd92cdce0d11489010b
199.pdf
Posted Aug 17, 2004
Authored by Xiaoyun Wang, Dengguo Feng, Xuejia Lai, Hongbo Yu | Site eprint.iacr.org

Whitepaper written on MD5 collisions that have been discovered.

tags | paper
MD5 | 7667d184375a8d968e9e107217f7e8ea
ssl-timing.pdf
Posted Mar 14, 2003
Authored by David Brumley, Dan Boneh

A paper written on timing attacks against OpenSSL 0.9.7. In this experiment, it shows that the extraction of private keys from an OpenSSL-based webserver is realistic. Monitoring about a million queries allows an attackers to remotely extract a 1024-bit RSA private key.

tags | paper
MD5 | 9eb9fc68b5cfe5c2d74a8becdf30b267
steg1.txt
Posted Sep 21, 2002
Authored by STE Jones | Site networkpenetration.com

Stenographied File Transfer Using Posix File Locks - How to transfer information to other users on secure systems by communicating with locked files. Includes some sample code that uses 32 locked files to transfer data on Posix systems.

tags | paper
MD5 | ea8bbd42018156e448eecba1b68a89b8
sub.txt
Posted Aug 30, 2002
Authored by Hexxeh

Substitution Ciphers - This paper discusses the five classic substitution ciphers and how they are solved.

tags | paper
MD5 | 34f7299219516aa6383c1b2658d339c7
trans.txt
Posted Aug 21, 2002
Authored by Hexxeh

Basic Transposition Ciphers - All they do is shuffle the characters.

tags | paper
MD5 | 165b8a06000834eb71e1c0229c59017c
ssh-timing.pdf
Posted Sep 3, 2001
Authored by Dawn Xiaodong Song, David Wagner, Xuqing Tian

Timing Analysis of Keystrokes and Timing Attacks on SSH - Watching the timing between keystrokes sent over SSH and other encrypted protocols, some information can be obtained about the contents of the packet.

tags | paper, protocol
MD5 | 3c0c3a2b81c3ccd3486d881d24be8460
Page 1 of 2
Back12Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close