Major flaw in outdated but widely-used SSL protocol ( POODLE )

Discussion in 'other security issues & news' started by MrBrian, Oct 14, 2014.

  1. 142395

    142395 Guest

    You can apply any flags even when Chrome is launched by other software, as long as Chrome is your default browser.

    Open regedit and search for 'chrome.exe" -- "%1"' without single quotation.
    In my Win7, those keys are found:
    HKEY_CLASSES_ROOT\ChromeHTML\shell\open\command
    HKEY_CLASSES_ROOT\ftp\shell\open\command
    HKEY_CLASSES_ROOT\http\shell\open\command
    HKEY_CLASSES_ROOT\https\shell\open\command
    HKEY_CURRENT_USER\Software\Classes\ChromeHTML\shell\open\command
    HKEY_CURRENT_USER\Software\Classes\ftp\shell\open\command
    HKEY_CURRENT_USER\Software\Classes\http\shell\open\command
    HKEY_CURRENT_USER\Software\Classes\https\shell\open\command
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ChromeHTML\shell\open\command

    Then, insert flags btwn chrome.exe" and -- "%1" just like this (be careful for space!)
    ...\Google\Chrome\Application\chrome.exe" --enable-strict-site-isolation --ssl-version-min=tls1 -- "%1"
    Do this for every entry, push F5 and exit regedit, then see whether those flags are applied.
     
  2. Minimalist

    Minimalist Registered Member

    Thank you for your suggestion @142395 ! It's really useful. For now I won't be changing all those registry settings. I will just wait until Google introduces this option in the browser settings.
     
  3. CloneRanger

    CloneRanger Registered Member

    Preventing POODLE attacks on Firefox, by opening about:config & searching for "security.enable," then setting it to "security.enable_ssl3" = false works for me, on both v3.6 & v27
     
  4. Compu KTed

    Compu KTed Registered Member

  5. MrBrian

    MrBrian Registered Member

    Deprecated according to Security.tls.version.* .
     
  6. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

  7. Veeshush

    Veeshush Registered Member

    Just out of curiosity I checked my 3DS browser: https://en.wikipedia.org/wiki/Internet_Browser_(Nintendo_3DS)
    Latest (1.7567) is vulnerable to Poodle. In fact the browser ONLY uses SSL3 and no TLS.

    While that might get fixed in an update at some point, it does make me think how many browsers are going to be vulnerable for the years to come.
     
  8. JRViejo

    JRViejo Super Moderator

    FYI. 2014-10-20 - FileZilla Client 3.9.0.6 released. (download available now!)
     
    Last edited: Oct 22, 2014
  9. 142395

    142395 Guest

    You're most welcome:)
     
  10. ronjor

    ronjor Global Moderator

    http://appleinsider.com/articles/14...cations-on-oct-29-due-to-poodle-vulnerability
     
  11. anon

    anon Registered Member

  12. ronjor

    ronjor Global Moderator

  13. MrBrian

    MrBrian Registered Member

    From POODLE Strikes (Bites?) Again:
     
  14. 142395

    142395 Guest

    Maybe it's not limited to Kaspersky, but I once found their mobile product still had Heartbleed vulnerability long after its disclosure.

    Those are reason I don't like idea of SSL scanning, because I can't put much trust on their automated certificate checking.
     
    Last edited by a moderator: Dec 9, 2014
  15. mirimir

    mirimir Registered Member

    The POODLE bites again
    https://www.imperialviolet.org/2014/12/08/poodleagain.html

    Wilders gets the overall rating "T" from SSLLabs ("If trust issues are ignored: A") :thumb:
     
  16. siljaline

    siljaline Registered Member

  17. ronjor

    ronjor Global Moderator

    https://www.us-cert.gov/ncas/alerts/TA14-290A
     
  18. ronjor

    ronjor Global Moderator

    http://krebsonsecurity.com/2014/12/poodle-bug-returns-bites-big-bank-sites
     
  19. Veeshush

    Veeshush Registered Member

  20. Mayahana

    Mayahana Banned

  21. JRViejo

    JRViejo Super Moderator

    Merged Threads to Continue Related Topic.
     
  22. siljaline

    siljaline Registered Member

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice