News
- +
Bugs put widely used DNS software at risk 27 April, 2006 08:17:38
Researchers have discovered new vulnerabilities in the widely used DNS server software.A number of flaws in the software that is used to administer the Internet's DNS (domain name system) has been discovered by researchers at Finland's University of Oulu. - +
Researchers find security flaw in SHA-1 algorithm 17 February, 2005 12:05:32
Scientists in China have written a paper describing a way to breaking SHA-1, an algorithm used for secure online communications.Security experts are warning that a security flaw has been found in a powerful data encryption algorithm, dubbed SHA-1, by a team of scientists from Shandong University in China. The three scientists are circulating a paper within the cryptographic research community that describes successful tests of a technique that could greatly reduce the speed with which SHA-1 could be compromised. - +
Mimosa debuts e-mail discovery 17 August, 2006 07:55:24
Mimosa Systems this week unveiled legal discovery and compliance modules for its e-mail archiving and continuous data protection software. - +
Experts warn some CAS arrays at risk 08 February, 2005 11:31:16
Security experts are warning against the use of a flawed hashing algorithm, MD5, for digital signatures to store data securely on increasingly popular content addressed storage (CAS) systems. - +
StorageTek gets serious about CAS 04 November, 2004 08:20:35
Storage Technology (StorageTek) is adding content-addressable store technology (CAS) to its range of storage products. According to an industry source, StorageTek is taking technology from Permabit and will announce an OEM deal in two weeks' time.
Click here for case studies, whitepapers and other useful vendor content WebCentral boosts Security and Reliability with Windows Server 2008
Dimension Data, La Trobe University and Windows Server 2008 partner to improve compliance
V/Line and Oakton use Microsoft SQL Server 2008 to develop an Executive HR Dashboard
Taking the Complexity out of IT Security
Taking an integrated approach to Spyware
November Infringement Alert
Australian water treatment company uses four GFI products to protect its network
Newsletter Subscription
Researchers have discovered a flaw in the MD5 algorithm that is used to provide a unique signature for data.
Xiaoyun Wang, a Chinese expert, and three colleagues have discovered the flaw in the hash function algorithm, which is used in applications, such as EMC's Centera content-addressable file store. The flaw was revealed at the Crypto 2004 conference.
A duplicated hash value is called a collision. Such a hash function is not un-crackable. It relies for its effectiveness on the great amount of time required to break it. Until the Chinese team's work, several million hours of compute time would have been needed. They showed that it could be done within a few hours on a standard PC.
If MD5 is flawed then data uniqueness cannot be guaranteed. Thus, for example, Centera's ability to guarantee data integrity would be compromised and compliance regimes based on it could no longer be trusted. MD5 is also used by the Apache web server to guarantee integrity of downloadable source code data on mirror sites. Sun also uses it in its Solaris fingerprint database to assure the integrity of downloadable binary files.
Another hash function algorithms also used in data integrity applications, were also shown to be vulnerable at the same conference. However the SHA-1 vulnerability is not as severe as that shown with MD5.
What is the real effect of this?
The MD5 flaw could be used by a malicious hacker to get corrupted code onto unsuspecting users' machines by means of a forged hash code that deceives the affected server into treating the corrupted code as safe.
As an instance of this it is reported by Byte and Switch that Val Bercovici, Network Appliance’s chief technical architect of ILM data protection and compliance solutions, thinks there is now a problem with content-addressed storage - single-instance storage as he puts it. The MD5 flaw provides hackers with a shortcut method to crack the algorithm.
What might happen is that a hacker could generate a script to create a binary file with the same content address as an existing file. This cloned file could be sent to the hacker as an e-mail attachment, which gets stored in an MD5-based system. Then the hacker mails out the original file, which happens to contain sensitive or secret data. Because its hash value is the same as the cloned attachment the MD5 system doesn't store it. There is then no record of the secret data being sent out.
While theoretically possible in the future this is not what the four Chinese researchers actually showed, according to Roy Sanford, EMC’s VP of CAS, mentioned in the same report. They showed random files could have duplicate addresses. They didn't generate a file which specifically had the same address as a target file. He also points out that Centera uses MD5 plus another EMC algorithm which has not been shown to be vulnerable. Centera files have not been demonstrated to be compromised.
Crypto 2004's chairman, Jim Hughes, is reported elsewhere as commenting that MD5 is now compromised and data integrity methods using it had better move on to use better algorithms.
ARN Member Login
When an IT disaster occurs, how handy it would be to push a button and start again as if nothing had happened.
Discover and learn more about CA XOSoft today.
Quantum announces General Availability of Industry's First Solution Designed to Match De-Duplication Functionality to Specific B 16 May, 2008 10:44:00
VIA Unveils the World’s Lowest Power x86 Processor on the World’s Smallest Board 15 May, 2008 14:03:00
WatchGuard Issues 45 Day IT Network Security Reminder for Achieving PCI DSS Compliance 15 May, 2008 11:33:00
AVG to Demo AVG Internet Security 8.0 at CeBIT 15 May, 2008 09:39:00
Media Alert: RSA AFCC detects “All-in-one” Zeus Trojan package for sale 15 May, 2008 09:00:00
Australian water treatment company uses four GFI products to protect its network
OSMOFLO, an Australian company, implemented a suite of four GFI products to protect its network from viruses and spam, to monitor and control internet usage and to save time and money on faxing.









