All articles

New DROWN bug: HTTPS is not always secure either

OpenSSL and DROWN

Did you always think you were safe when websites displayed a green box with their name before the web address? Unfortunately not. A new vulnerability has been discovered in website communication security, meaning websites may be less secure than they claim. The underlying technology, SSL, recognisable by HTTPS in the web address and the green box, turns out to be relatively easy to break in some cases. Initial estimates suggest that around 33% of websites secured this way worldwide are vulnerable.

What is your risk?

In principle, hackers can intercept all data exchanged between a website visitor and the website. This could include usernames and passwords, but also credit card details, financial information or confidential email traffic. The risk affects not only websites but also email servers, online shops and chat forums: anything using SSL may be vulnerable.

Why does this happen?

DROWN, as this new vulnerability is called, targets the use of TLS and SSL v2. TLS is a modern technology offering strong security, but many systems still support its predecessor, SSL v2. Research puts this at up to 17% of all HTTPS servers. Sometimes this is deliberate, but often it is unintentional, caused by incorrect configuration or overdue maintenance.

A second risk arises when an SSL private key is shared across servers, such as a web server, email server and e-commerce server, and one of them allows SSL v2 traffic. Even if only one of the three supports SSL v2, all three are vulnerable to DROWN, with all the consequences that entails. This risk affects another 16% of HTTPS servers, bringing the total to 33% vulnerable servers.

What can you do as a website visitor? Unfortunately, nothing.

This problem can only be resolved on the server side; users and website visitors cannot protect themselves against it. The most important step is to stop using SSL v2 and replace it with more modern, secure technologies. Measures are available for virtually all familiar products, including OpenSSL, Microsoft IIS and Apache, to modify systems and prevent the risks of DROWN.

More technical information is available at https://drownattack.com/drown-attack-paper.pdf

How can SECWATCH help?

If you have a SECWATCH Next-Gen Vulnerability Assessment subscription, we automatically check your systems and report our findings, including recommendations. We are also available if you do not yet have a security subscription with us. Contact us for a tailored security scan.


Back to all articles