exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

GSTOOL 4.7 Insecure Encryption

GSTOOL 4.7 Insecure Encryption
Posted Sep 11, 2013
Authored by Jan Schejbal

GSTOOL versions 3.0 through 4.7 contain an insecure encryption feature using the non-public CHIASMUS block cipher.

tags | advisory
SHA-256 | 3cc88f54737c061f14999839c9225e374801d4a5b0c96665eeeb60c1ba4fac3a

GSTOOL 4.7 Insecure Encryption

Change Mirror Download
== Insecure CHIASMUS encryption in GSTOOL ==
GSTOOL versions 3.0 to 4.7 (inclusive) contain an insecure encryption
feature using the non-public CHIASMUS block cipher. Due to the use of an
insecure PRNG for key generation, files encrypted using the encryption
feature of this tool can be decrypted without knowledge of the key
within seconds to minutes.

The affected versions of GSTOOL were developed by Steria Mummert
Consulting for the German Federal Office for Information Security
(Bundesamt für Sicherheit in der Informationstechnik, BSI) and released
by the BSI.

We reported the issue to the BSI in November 2011. The BSI issued an
advisory warning users to stop using the encryption feature in the same
month. A patch disabling the vulnerable encryption feature was released
in June 2013. We later learned that the issue was independently
discovered by Felix Schuster in 2009.

For full details including further issues found, please see the German
advisory, available at
http://janschejbal.wordpress.com/2013/09/11/advisory-unsichere-verschluesselung-bei-gstool/.
Since this is an implementation issue, the CHIASMUS block cipher itself
and other products (e.g. Chiasmus for Windows) using the CHIASMUS block
cipher are NOT affected.

Kind regards,
Jan Schejbal
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    0 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close