Modernizing Authentication — What It Takes to Transform Secure Access
A German hacker group has released a new DDoS tool designed to enable a single PC to take down a Web server using a secure connection.
"The THC-SSL-DOS tool ... purportedly exploits a flaw in Secure Sockets Layer (SSL) renegotiation protocol by overwhelming the system with multiple requests for secure connections," writes CNET News' Steven Musil. "SSL renegotiation allows Web sites to create a new security key over an already established SSL connection."
"A German group known as [The] Hacker's Choice said it released the exploit to bring attention to flaws in SSL, which allows sensitive data to flow between Web sites and an individual user's computer without being intercepted," Musil writes.
Go to "New attack tool targets Web servers using secure connections" to read the details.
For regular security news updates, follow eSecurityPlanet on Twitter: @eSecurityP.