Critical Windows 10 vulnerability used to Rickroll the NSA and Github

Chrome on Windows 10 as it Rickrolls the NSA.

Enlarge / Chrome on Windows 10 as it Rickrolls the NSA. (credit: https://twitter.com/saleemrash1d/status/1217519809732259840/photo/1)

Less than a day after Microsoft disclosed one of the most critical Windows vulnerabilities ever, a security researcher has demonstrated how attackers can exploit it to cryptographically impersonate any website or server on the Internet.

Researcher Saleem Rashid on Wednesday tweeted images of the video "Never Gonna Give You Up," by 1980s heartthrob Rick Astley, playing on Github.com and NSA.gov. The digital sleight of hand is known as Rickrolling and is often used as a humorous and benign way to demonstrate serious security flaws. In this case, Rashid's exploit causes both the Edge and Chrome browsers to spoof the HTTPS verified websites of Github and the National Security Agency. Brave and other Chrome derivatives, as well as Internet Explorer, are also likely to fall to the same trick. (There's no indication Firefox is affected.)

Rashid's simulated attack exploits CVE-2020-0601, the critical vulnerability that Microsoft patched on Tuesday after receiving a private tipoff from the NSA. As Ars reported, the flaw can completely break certificate validation for websites, software updates, VPNs, and other security-critical computer uses. It affects Windows 10 systems, including server versions Windows Server 2016 and Windows Server 2019. Other versions of Windows are unaffected.

Read 16 remaining paragraphs | Comments

https://arstechnica.com/?p=1644337

Source: Ars Technica

By:

Kami’s wireless outdoor camera keeps it simple
Kamis wireless outdoor camera keeps it simple ...
hide.me VPN boosts data transfer limit
hide.me VPN boosts data transfer limit ...
Mysterious budget Redmi phone gets certified by FCC
Mysterious budget Redmi phone gets certified by FC ...
Pumpkin Face Carving Challenge
Pumpkin Face Carving Challenge ...
Flexibits launches major Fantastical update
Flexibits launches major Fantastical update ...
This tiny chip is why you may need a new laptop soon
This tiny chip is why you may need a new laptop so ...