Florian Maury · @x_cli
405 followers · 1633 posts · Server infosec.exchange

eprint.iacr.org/2023/331.pdf

"A Vulnerability in Implementations of SHA-3"

> we show how this vulnerability can be used to construct second preimages and preimages for the mplementation, and we provide a pecially constructed file that, when ashed, allows the attacker to execute arbitrary code on the victim’s device

đŸ’„

#security #hash #sha3 #crypto

Last updated 1 year ago

tkteo · @tkteo
39 followers · 1219 posts · Server infosec.exchange

Paper 2023/331 A Vulnerability in Implementations of SHA-3, SHAKE, EdDSA, and Other NIST-Approved Algorithm

Abstract

This paper describes a vulnerability in several implementations of the Secure Hash Algorithm 3 (SHA-3) that have been released by its designers. The vulnerability has been present since the final-round update of Keccak was submitted to the National Institute of Standards and Technology (NIST) SHA-3 hash function competition in January 2011, and is present in the eXtended Keccak Code Package (XKCP) of the Keccak team. It affects all software projects that have integrated this code, such as the scripting languages Python and PHP Hypertext Preprocessor (PHP). The vulnerability is a buffer overflow that allows attacker-controlled values to be eXclusive-ORed (XORed) into memory (without any restrictions on values to be XORed and even far beyond the location of the original buffer), thereby making many standard protection measures against buffer overflows (e.g., canary values) completely ineffective. First, we provide Python and PHP scripts that cause segmentation faults when vulnerable versions of the interpreters are used. Then, we show how this vulnerability can be used to construct second preimages and preimages for the implementation, and we provide a specially constructed file that, when hashed, allows the attacker to execute arbitrary code on the victim's device. The vulnerability applies to all hash value sizes, and all 64-bit Windows, Linux, and macOS operating systems, and may also impact cryptographic algorithms that require SHA-3 or its variants, such as the Edwards-curve Digital Signature Algorithm (EdDSA) when the Edwards448 curve is used. We introduce the Init-Update-Final Test (IUFT) to detect this vulnerability in implementations.

eprint.iacr.org/2023/331

#cryptography #encryption #sha #sha3 #cybersecurity #hash #hashing #algorithm #algorithms #nist #nistcybersecurityframework

Last updated 1 year ago

Marco Bellaccini · @lasagnasec
15 followers · 76 posts · Server infosec.exchange

The only good part is that SHA3 is still not that widespread.
eprint.iacr.org/2023/331

#sha3 #cve_2022_37454

Last updated 1 year ago

Jens · @schegge42
31 followers · 312 posts · Server nrw.social

Sichere Ahnen PrĂŒfung mit Cryptographic Hashes

Bei der Erstellung eigner StammbĂ€ume gibt es immer wieder den Wunsch in anderen DatenbestĂ€nden nach Familienangehörigen zu suchen. Dabei ergibt sich jedoch das Problem, dann personenbezogene Daten an andere versendet werden mĂŒssen.

schegge.de/2023/03/sichere-ahn

-Pattern -256

#algorithmen #bestpractices #Design #java #web #sha #sha3

Last updated 1 year ago

Jens · @schegge42
31 followers · 311 posts · Server nrw.social

Sichere Ahnen PrĂŒfung mit Cryptographic Hashes

Bei der Erstellung eigner StammbĂ€ume gibt es immer wieder den Wunsch in anderen DatenbestĂ€nden nach Familienangehörigen zu suchen. Dabei ergibt sich jedoch das Problem, dann personenbezogene Daten an andere versendet werden mĂŒssen.

schegge.de/2023/03/sichere-ahn

-Pattern -256

#algorithmen #bestpractices #Design #java #web #sha #sha3

Last updated 1 year ago

With full joy I will be talking in 2023 about a free system for cataloguing challenging museum-libraries items like manuscripts and books with dedication/marginalia.

libreplanet.org/2023/program/

@fsf

#libreplanet #freesoftwarefoundation #mesicon #linux #apache #mysql #php #sha3

Last updated 1 year ago

With full joy I will be talking in 2023 about a free system for cataloguing challenging museum-libraries items like manuscripts and books with dedication/marginalia.

libreplanet.org/2023/program/

@fsf

#libreplanet #freesoftwarefoundation #mesicon #linux #apache #mysql #php #sha3

Last updated 1 year ago

RĂ©mi Ferrand · @remiferrand
4 followers · 9 posts · Server mastodon.gougere.fr

⚠ CVE-2022-37454 - Buffer overflow in the module in 3.10 and older 🐍 python-security.readthedocs.io

#sha3 #python #security

Last updated 2 years ago