December 2, 2007
2:50 pm

Marc Stevens, Arjen K. Lenstra, and Benne de Weger have released their paper 'Vulnerability of software integrity and code signing applications to chosen-prefix collisions for MD5'. It describes a reproducible attack on MD5 algorithms to fake software signatures. Researchers start off with two simplistic Windows applications — HelloWorld.exe and GoodbyeWorld.exe, and apply a known prefix attack that makes md5() signatures for both of the applications identical. Researchers point out: 'For abusing a chosen-prefix collision on a software integrity protection or a code signing scheme, the attacker should be able to manipulate the files before they are being hashed and/or signed. This may mean that the attacker needs insider access to the party operating the trusted software integrity protection or code signing process.'

Security, Desktop, Software, Application, Encryption, MD5, Algorithm

Source:? Slashdot

Loading

Contextual Related Posts:

No followup yet

Leave a Response

Comment Preview
« Windows HPC Server 2008 Beta1Nokia energy profiler app »
Feed Icon

Subscribe via RSS or email: