Ich stimme der Verwendung von Cookies zu. Auch wenn ich diese Website weiter nutze, gilt dies als Zustimmung.

Bitte lesen und akzeptieren Sie die Datenschutzinformation und Cookie-Informationen, damit Sie unser Angebot weiter nutzen können. Natürlich können Sie diese Einwilligung jederzeit widerrufen.





Severe Vulnerabilities Discovered in Software to Protect Internet Routing (FOTO)

APA-OTS-Meldungen aus dem Finanzsektor in der "BSN Extended Version"
Wichtige Originaltextaussendungen aus der Branche. Wir ergänzen vollautomatisch Bilder aus dem Fundus von photaq.com und Aktieninformationen aus dem Börse Social Network. Wer eine Korrektur zu den Beiträgen wünscht: mailto:office@boerse-social.com . Wir wiederum übernehmen keinerlei Haftung für Augenerkrankungen aufgrund von geballtem Grossbuchstabeneinsatz der Aussender. Wir meinen: Firmennamen, die länger als drei Buchstaben sind, schreibt man nicht durchgängig in Grossbuchstaben (Versalien).
Magazine aktuell


#gabb aktuell



11.04.2024, 3597 Zeichen

Frankfurt and Darmstadt (ots) - A research team from the National Research Center for Applied Cybersecurity ATHENE led by Prof. Dr. Haya Schulmann has uncovered 18 vulnerabilities in crucial software components of Resource Public Key Infrastructure (RPKI). RPKI is an Internet standard meant to protect Internet traffic from being hijacked by hackers. By now, all affected vendors provided patches for their products. The vulnerabilities could have had devastating consequences: Internet hijacks have already been exploited, e.g., for phishing passwords and other sensitive information, tricking certificate authorities into issuing fraudulent Web certificates, stealing cryptocurrency, distributing malware, and poisoning caches of DNS servers.
The ATHENE team consisting of Prof. Dr. Haya Schulmann and Niklas Vogel, both from Goethe University of Frankfurt, Donika Mirdita from TU Darmstadt, and Prof. Dr. Michael Waidner from TU Darmstadt and Fraunhofer SIT uncovered and disclosed 18 vulnerabilities. The National Vulnerability Database (NVD), operated by the US National Institute of Standards and Technology (NIST), assigned five Common Vulnerabilities and Exposures (CVE) entries to these vulnerabilities, some critical with a score of 9.3 out of 10. The team used a testing tool, CURE, which they developed specifically for this project and which ATHENE makes available free of charge to all developers of RPKI software. The researchers found vulnerabilities in all popular implementations of the validator component of RPKI. They range between crashes, violation of standard behavior, and even severe bugs that allow a network adversary to completely take over an RPKI certificate hierarchy in order to inject its own trust anchor - effectively being able to forge authentic and valid yet bogus routing information (i.e., BGP announcements). It is unknown whether any of the vulnerabilities were already exploited by hackers in the wild.
RPKI is a relatively new standard. Today, about 50% of the Internet's network prefixes are covered by RPKI certificates, and 37.8% of all Internet domains validate RPKI certificates. In particular, many large providers and operators support RPKI, e.g., Amazon Web Services, Cogent, Deutsche Telekom, Level 3, and Zayo.
The research work was carried out in the ATHENE research area Analytic Based Cybersecurity (ABC) (more information at https://abc.athene-center.de/en/ ) and appeared at the 2024 Network and Distributed System Security (NDSS) Symposium in San Diego, California, USA. The research paper can be downloaded from https://www.ndss-symposium.org/ndss-paper/the-cure-to-vulnera... -in-rpki-validation/. The testing tool CURE developed and used by the researchers to uncover the vulnerabilities can be downloaded from https://github.com/rp-cure/rp-cure.
The National Research Center for Applied Cybersecurity ATHENE is a research center of the Fraunhofer Society that brings together the Fraunhofer Institutes for Secure Information Technology (SIT) and for Computer Graphics Research (IGD), Technische Universität Darmstadt, Goethe-Universität Frankfurt am Main, and Darmstadt University of Applied Sciences. With more than 600 scientists, ATHENE is Europe's most prominent cybersecurity research center and Germany's leading scientific research institution in this domain. ATHENE is supported by the German Federal Ministry of Education and Research (BMBF) and the Hessian Ministry for Higher Education, Research, Science and the Arts (HMWK). Further information about ATHENE can be found at https://www.athene-center.de/en/.
Digital press kit: http://www.ots.at/pressemappe/DE173495/aom

BSN Podcasts
Christian Drastil: Wiener Börse Plausch

SportWoche Podcast #122: Hans Huber über Vienna-Fan Richard Lugner (1932-2024), Frauen und den Erfinder der Mörtel-Bezeichnung




 

Aktien auf dem Radar:Rosenbauer, FACC, CA Immo, Warimpex, Addiko Bank, Lenzing, Wienerberger, ams-Osram, Immofinanz, OMV, RBI, voestalpine, Josef Manner & Comp. AG, Marinomed Biotech, Oberbank AG Stamm, Flughafen Wien, Pierer Mobility, Kapsch TrafficCom, Agrana, Amag, Erste Group, EVN, Österreichische Post, RHI Magnesita, S Immo, Telekom Austria, Uniqa, VIG, Bayer, Hannover Rück, Siemens Healthineers.


Random Partner

RWT AG
Die Firma RWT Hornegger & Thor GmbH wurde 1999 von den beiden Geschäftsführern Hannes Hornegger und Reinhard Thor gegründet. Seitdem ist das Unternehmen kontinuierlich, auf einen derzeitigen Stand von ca. 30 Mitarbeitern, gewachsen. Das Unternehmen ist in den Bereichen Werkzeugbau, Formenbau, Prototypenbau und Baugruppenfertigung tätig und stellt des Weiteren moderne Motorkomponenten und Präzisionsteile her.

>> Besuchen Sie 68 weitere Partner auf boerse-social.com/partner


Mehr aktuelle OTS-Meldungen HIER

Useletter

Die Useletter "Morning Xpresso" und "Evening Xtrakt" heben sich deutlich von den gängigen Newslettern ab. Beispiele ansehen bzw. kostenfrei anmelden. Wichtige Börse-Infos garantiert.

Newsletter abonnieren

Runplugged

Infos über neue Financial Literacy Audio Files für die Runplugged App
(kostenfrei downloaden über http://runplugged.com/spreadit)

per Newsletter erhalten


Meistgelesen
>> mehr





PIR-Zeichnungsprodukte
AT0000A39G75
AT0000A3BPW4
AT0000A3DG27
Newsflow
>> mehr

Börse Social Club Board
>> mehr
    BSN Vola-Event Bayer
    BSN Vola-Event Warimpex
    #gabb #1668

    Featured Partner Video

    Wiener Börse Party #715: Doppelte Vorsicht bei Marinomed vgl. Varta, FACC unter starken Zahlenlegern mit bester Börsereaktion

    Die Wiener Börse Party ist ein Podcastprojekt für Audio-CD.at von Christian Drastil Comm.. Unter dem Motto „Market & Me“ berichtet Christian Drastil über das Tagesgeschehen an der Wiener Börse. Inh...

    Books josefchladek.com

    Adolf Čejchan
    Ústí nad Labem
    1965
    Severočeské krajské nakladatelství

    Erik Hinz
    Twenty-one Years in One Second
    2015
    Peperoni Books

    Mikael Siirilä
    Here, In Absence
    2024
    IIKKI

    Ros Boisier
    Inside
    2024
    Muga / Ediciones Posibles

    Sergio Castañeira
    Limbo
    2023
    ediciones anómalas

    Severe Vulnerabilities Discovered in Software to Protect Internet Routing (FOTO)


    11.04.2024, 3597 Zeichen

    Frankfurt and Darmstadt (ots) - A research team from the National Research Center for Applied Cybersecurity ATHENE led by Prof. Dr. Haya Schulmann has uncovered 18 vulnerabilities in crucial software components of Resource Public Key Infrastructure (RPKI). RPKI is an Internet standard meant to protect Internet traffic from being hijacked by hackers. By now, all affected vendors provided patches for their products. The vulnerabilities could have had devastating consequences: Internet hijacks have already been exploited, e.g., for phishing passwords and other sensitive information, tricking certificate authorities into issuing fraudulent Web certificates, stealing cryptocurrency, distributing malware, and poisoning caches of DNS servers.
    The ATHENE team consisting of Prof. Dr. Haya Schulmann and Niklas Vogel, both from Goethe University of Frankfurt, Donika Mirdita from TU Darmstadt, and Prof. Dr. Michael Waidner from TU Darmstadt and Fraunhofer SIT uncovered and disclosed 18 vulnerabilities. The National Vulnerability Database (NVD), operated by the US National Institute of Standards and Technology (NIST), assigned five Common Vulnerabilities and Exposures (CVE) entries to these vulnerabilities, some critical with a score of 9.3 out of 10. The team used a testing tool, CURE, which they developed specifically for this project and which ATHENE makes available free of charge to all developers of RPKI software. The researchers found vulnerabilities in all popular implementations of the validator component of RPKI. They range between crashes, violation of standard behavior, and even severe bugs that allow a network adversary to completely take over an RPKI certificate hierarchy in order to inject its own trust anchor - effectively being able to forge authentic and valid yet bogus routing information (i.e., BGP announcements). It is unknown whether any of the vulnerabilities were already exploited by hackers in the wild.
    RPKI is a relatively new standard. Today, about 50% of the Internet's network prefixes are covered by RPKI certificates, and 37.8% of all Internet domains validate RPKI certificates. In particular, many large providers and operators support RPKI, e.g., Amazon Web Services, Cogent, Deutsche Telekom, Level 3, and Zayo.
    The research work was carried out in the ATHENE research area Analytic Based Cybersecurity (ABC) (more information at https://abc.athene-center.de/en/ ) and appeared at the 2024 Network and Distributed System Security (NDSS) Symposium in San Diego, California, USA. The research paper can be downloaded from https://www.ndss-symposium.org/ndss-paper/the-cure-to-vulnera... -in-rpki-validation/. The testing tool CURE developed and used by the researchers to uncover the vulnerabilities can be downloaded from https://github.com/rp-cure/rp-cure.
    The National Research Center for Applied Cybersecurity ATHENE is a research center of the Fraunhofer Society that brings together the Fraunhofer Institutes for Secure Information Technology (SIT) and for Computer Graphics Research (IGD), Technische Universität Darmstadt, Goethe-Universität Frankfurt am Main, and Darmstadt University of Applied Sciences. With more than 600 scientists, ATHENE is Europe's most prominent cybersecurity research center and Germany's leading scientific research institution in this domain. ATHENE is supported by the German Federal Ministry of Education and Research (BMBF) and the Hessian Ministry for Higher Education, Research, Science and the Arts (HMWK). Further information about ATHENE can be found at https://www.athene-center.de/en/.
    Digital press kit: http://www.ots.at/pressemappe/DE173495/aom

    BSN Podcasts
    Christian Drastil: Wiener Börse Plausch

    SportWoche Podcast #122: Hans Huber über Vienna-Fan Richard Lugner (1932-2024), Frauen und den Erfinder der Mörtel-Bezeichnung




     

    Aktien auf dem Radar:Rosenbauer, FACC, CA Immo, Warimpex, Addiko Bank, Lenzing, Wienerberger, ams-Osram, Immofinanz, OMV, RBI, voestalpine, Josef Manner & Comp. AG, Marinomed Biotech, Oberbank AG Stamm, Flughafen Wien, Pierer Mobility, Kapsch TrafficCom, Agrana, Amag, Erste Group, EVN, Österreichische Post, RHI Magnesita, S Immo, Telekom Austria, Uniqa, VIG, Bayer, Hannover Rück, Siemens Healthineers.


    Random Partner

    RWT AG
    Die Firma RWT Hornegger & Thor GmbH wurde 1999 von den beiden Geschäftsführern Hannes Hornegger und Reinhard Thor gegründet. Seitdem ist das Unternehmen kontinuierlich, auf einen derzeitigen Stand von ca. 30 Mitarbeitern, gewachsen. Das Unternehmen ist in den Bereichen Werkzeugbau, Formenbau, Prototypenbau und Baugruppenfertigung tätig und stellt des Weiteren moderne Motorkomponenten und Präzisionsteile her.

    >> Besuchen Sie 68 weitere Partner auf boerse-social.com/partner


    Mehr aktuelle OTS-Meldungen HIER

    Useletter

    Die Useletter "Morning Xpresso" und "Evening Xtrakt" heben sich deutlich von den gängigen Newslettern ab. Beispiele ansehen bzw. kostenfrei anmelden. Wichtige Börse-Infos garantiert.

    Newsletter abonnieren

    Runplugged

    Infos über neue Financial Literacy Audio Files für die Runplugged App
    (kostenfrei downloaden über http://runplugged.com/spreadit)

    per Newsletter erhalten


    Meistgelesen
    >> mehr





    PIR-Zeichnungsprodukte
    AT0000A39G75
    AT0000A3BPW4
    AT0000A3DG27
    Newsflow
    >> mehr

    Börse Social Club Board
    >> mehr
      BSN Vola-Event Bayer
      BSN Vola-Event Warimpex
      #gabb #1668

      Featured Partner Video

      Wiener Börse Party #715: Doppelte Vorsicht bei Marinomed vgl. Varta, FACC unter starken Zahlenlegern mit bester Börsereaktion

      Die Wiener Börse Party ist ein Podcastprojekt für Audio-CD.at von Christian Drastil Comm.. Unter dem Motto „Market & Me“ berichtet Christian Drastil über das Tagesgeschehen an der Wiener Börse. Inh...

      Books josefchladek.com

      Erik Hinz
      Twenty-one Years in One Second
      2015
      Peperoni Books

      Nikita Teryoshin
      Nothing Personal
      2024
      GOST

      Mimi Plumb
      Landfall
      2018
      TBW Books

      Kazumi Kurigami
      操上 和美
      2002
      Switch Publishing Co Ltd

      Dominic Turner
      False friends
      2023
      Self published