New software application to protect computers against SSL Certificate Null Byte Poisoning vulnerability

 {SonicWALL, Inc~{The firm}~SonicWall~Sonic}~SoniWall~{The firm}~SonicWall~Sonic}.a leader in network infrastructure security, has launched a new software that provides security against threat of these so-called SSL Certificate Null Byte Poisoning vulnerabiltiy. Users of the SonicWall Internet security‘s  Unified Threat Management Firewall technology, which protects against viruses, Trojans, worms and other threats and vulnerabilities, automatically receive updated signatures designed to repel security threats.

Various browser and non-browser based SSL implementations will be vulnerable for hijacking as your computer is incapable of defending itself from attacks. An attacker will obtain null byte stuffed certificate to resemble the origin of the content, making your computer vulnerable to attacks because your system cannot distinguish if the machine is under attack from third party source.

In addition, SSL sessions compromised as a result of the above mentioned vulnerability, can be used to install unwanted trojans and malware on the victim’s computer.

The vulnerability was first publicly disclosed during BlackHat security conference briefings in Las Vegas on July 29-30, 2009. On July 31, 2009, users of SonicWALL internet security‘s Unified Threat Management technology received updated signatures designed to protect against this threat. SonicWALL has issued the following IPS signature

SonicWALL has developed unique technologies to deliver zero day gateway anti-virus, anti-spyware and intrusion prevention signatures to its subscribers on a continual basis, allowing them to defend against new and existing Internet attacks and exploits such as phishing, viruses, DHA or DoS attacks and more. We are happy to report that computers with installed SonicWAll’s gateway threat prevention services have not been attacked by exploiting this weakness.

SonicWALL, Inc~{The firm}~SonicWall~Sonic}. the leader in network security, focuses on developing solutions that remove the cost and complexity out of managing a secure network environment. With over one million award-winning appliances shipped through its global network of ten thousand channel partners, SonicWALL Internet security provides end-to-end solutions including Firewalls, SSL VPN’s, Email Security and Continuoinous Data Protection that collectively ensure robust, secure network protection.

 

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • NewsVine
  • Reddit
  • StumbleUpon
  • Google Bookmarks
  • Yahoo! Buzz
  • Twitter
  • Technorati
  • Live
  • LinkedIn
  • MySpace

Leave a Reply