Go Back   FlashFXP Forums > FlashFXP > Release Archive > Website

Website Comments, Suggestions, Questions, Concerns, Fan mail, Hate mail, Whatever goes.

 
 
Thread Tools
Old 04-05-2005, 03:22 PM   #1
Member
ioFTPD Registered User
 
Join Date: Mar 2005
Posts: 31
Default MD5 break open

According to spacedaily.com Md5 cipher is break open.
http://www.spacedaily.com/news/cyberwar-05i.html

Maybe its a time to implement something more complex?
Like this:

234 AUTH TLS successful
Connected. Negotiating TLSv1 session..
TLSv1 negotiation successful...
TLSv1 encrypted session using cipher DHE-DSS-AES256-SHA (256 bits)

This is welcome message from linux glftpd.
router is offline  
Old 04-05-2005, 03:38 PM   #2
Senior Member
ioFTPD Scripter
 
Join Date: Aug 2002
Posts: 535
Default

this is with ioftpd:

234 AUTH TLS successful.
Connected. Negotiating SSL/TLS session..
SSL/TLS negotiation successful...
TLSv1/SSLv3 encrypted session using cipher DES-CBC3-SHA (168 bits)

isn't that enough ?

bounty
bounty is offline  
Old 04-05-2005, 04:14 PM   #3
Too much time...
FlashFXP Beta Tester
ioFTPD Scripter
 
Join Date: May 2003
Posts: 1,364
Default

router: The hash collisions found in MD5 and SHA-1 (and others) only affect hashes, not HMAC based handshakes (supported by SSL v3 and TLS v1).

However, the SHA-1 password hashes stored in ioFTPD's user-files would be affected. But this is a very low-risk threat; since the attacker would need physical access to ioFTPD's user-files to leverage hash collision during brute forcing.
neoxed is offline  
Old 04-11-2005, 12:57 PM   #4
Member
ioFTPD Registered User
 
Join Date: Mar 2005
Posts: 31
Default

bounty:
How you have created your cer?

Update: sorry for double topic.
I already find the answer.
router is offline  
 
Create a free account to browse our forums without ads



Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
MasterLock v1.0 beta 1 bigstar Software 29 10-26-2007 03:58 AM
New User Needs Help ep2002 General Discussions 9 01-07-2005 01:50 AM


All times are GMT -5. The time now is 01:54 AM.