{SonicWALL, Inc~{The firm}~SonicWall~Sonic}~Our firm~{The firm}~SonicWall~Sonic}., a leading secure network infrastructure company, has announced the development of a new application that would provide protection against SSL Certificate Null Byte Poisoning vulnerability. Users of the SonicWall Internet security’s  Unified Threat Management Firewall technology, which protects against viruses, Trojans, worms and other threats and vulnerabilities, automatically receive updated signatures designed to repel security threats.

Various browser and non-browser based SSL implementations will be vulnerable for hijacking as your computer is incapable of defending itself from attacks. Once an attacker successfully obtains a specially crafted null byte stuffed certificate designed to imitate the origin content server, privacy of the data can be compromised since there will be no distinguishable notification to the user that the secure connection has been intercepted by an unknown 3rd party.

In addition, SSL sessions compromised as a result of the above mentioned vulnerability, can be used to install unwanted trojans and malware on the victim’s computer.

The problem was first brouched during the July 29-30, 2009 BalckHat security conference session in Las Vegas. On July 31, 2009, users of SonicWALL internet security’s Unified Threat Management technology received updated signatures designed to protect against this threat. SonicWALL has issued the following IPS signature

SonicWALL has developed unique technologies to deliver zero day gateway anti-virus, anti-spyware and intrusion prevention signatures to its subscribers on a continual basis, allowing them to defend against new and existing Internet attacks and exploits such as phishing, viruses, DHA or DoS attacks and more. All computers with installed SonicWAll’s gateway threat prevention services have reported they have not experienced any attacks through the exploitation of said weakness.

The company~{The firm}~SonicWall~Sonic}. the leader in network security, focuses on developing solutions that remove the cost and complexity out of managing a secure network environment. With over one million award-winning appliances shipped through its global network of ten thousand channel partners, SonicWALL Internet security provides end-to-end solutions including Firewalls, SSL VPN’s, Email Security and Continuoinous Data Protection that collectively ensure robust, secure network protection.

 

Leave a Reply



Site Navigation