Flawed cryptography is leaving people using IPsec security protocols vulnerable to hacking, according to the UK's National Infrastructure Security Coordination Centre (NISCC).
The organisation has released an advisory about the discovery of three key flaws in the Encapsulating Security Payload (ESP) that provides base-level encryption of data, typically travelling though virtual private networks.
"An attacker could modify sections of the IPsec packet, causing either the cleartext inner packet to be redirected or a network host to generate an error message," warned NISCC.
"In the latter case, these errors are relayed via the Internet Control Message Protocol. Because of the Protocol's design, these messages directly reveal segments of the header and payload of the inner datagram in cleartext.
"The attacks have been implemented and demonstrated to work under realistic conditions."
The organisation rates the flaws as 'highly critical' and added that the Authentication Header protocols that guarantee the authenticity of data packets are also vulnerable.
The advisory provides three ways to work around the problem, including reconfiguring the ESP system and using Authentication Header and ESP simultaneously to defeat eavesdroppers.
Portal Manager, Leeds In charge of the Portal Management team, you'll manage the day to day operations of the portal and provide editorial function and guidance. You'll understand and own the portal's strategic aim and ... more >
Project and Portfolio Managers, London, £35,847 - £46,357 The Advisory, Conciliation and Arbitration Service (ACAS) is a publicly-funded body with over 30 years experience of working with employers, employees and trade unions to deliver better ... more >
Graduate SQL Developer, Aylesbury, Buckinghamshire, Excellent Salary + Benefits Grass Roots are one of the Sunday Times Top 100 companies to work for (2007 and 2008). Established in 1980, we're part of the Grass Roots ... more >
Sr. Software Architect, Bristol, Competitive and Relocation Money Available Job Description: This position is for a Systems Analyst/SW Engineer for the Boeing Defence UK office in Bristol. The candidate will lead software development activities in ... more >More job opportunities