Table of Contents
Learn about DUHK attacks allow hackers to obtain encryption keys for VPN, who may be affected, and which practical steps users or administrators can take to reduce exposure.
DUHK Attacks Allow Hackers to Obtain Encryption Keys for VPN and Web Browsing Overview
DUHK - don't Use Hard-coded Keys - is a new dangerous encryption executable vulnerability that allows an attacker to recover the encryption key used to secure VPN connections and web sessions.
DUHK is the third vulnerability related to encryption discovered this month, after attacking Wi-Fi KRACK and attacking ROCA.
This vulnerability exists on many devices of many vendors, including Fortinet, Cisco, TechGuard, where the device uses ANSI X9. 31 RNG - an algorithm to generate pseudo random numbers - along with the key hard-coded (just embedding it directly into source or fixed data instead of taking from external sources).
Before being removed from the list of FIPS-approved random number sequence algorithms approved in January 2016, ANSI X9. 31 RNG is used in many coding standards for more than 30 years.
The pseudo random number generator (PRNG) does not generate random numbers. In essence, it is an algorithm that creates a series of bits based on secret values originally called 'seeds' and creates the current state. This bit sequence is always the same due to the same initial values.
Some vendors store this 'secret seed' into their product source code.
Discovered by cryptanalysts Shaanan Cohney, Nadia Heninger and Matthew Green, DUHK, known as 'status restoration attack', allows intermediaries who already know the value of seeds restore the current value after viewing the output data.
With those two values, the attacker uses to recalculate the encryption key, restoring the encrypted data.
'To describe the reality, we created passive decoding attack on FortiGate VPN product with FortiOS version 4', the researchers said. 'We scanned at least 23, 000 devices with public IPv4 addresses running FortiOS versions containing vulnerabilities'. Below is an incomplete list of influential devices with the same version.
Vendor products containing vulnerabilities are vulnerable to DUHK attacks
Researchers have also published in-depth research material on the DUHK attack website at this address. https://duhkattack. com/
Security note: Threat conditions and vendor guidance can change. Install current updates and verify any advisory with the official vendor before taking action.
FAQ
Why does DUHK Attacks Allow Hackers to Obtain Encryption Keys for VPN and Web Browsing matter?
Learn about DUHK attacks allow hackers to obtain encryption keys for VPN, who may be affected, and which practical steps users or administrators can take to reduce exposure.
Who may be affected by this issue?
The impact depends on the affected product, version, account, device, or network. Review the article details and the vendor's current advisory to confirm whether your environment is exposed.
How can users reduce the risk?
Install current security updates, use official downloads, enable strong account protection, maintain tested backups, and follow the latest guidance from the relevant vendor.
Reader Comments 0
Sign in with email or Google to join the discussion.