Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-dev: Re: [Wireshark-dev] performing cpu/time intensive computation in a protocol dissector

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Sake Blok <sake@xxxxxxxxxx>
Date: Tue, 5 Aug 2008 20:28:05 +0200

On Tue, Aug 05, 2008 at 02:22:58PM +0200, Paolo Abeni wrote:
> hello,
> 
> In a pending patch for the SSL dissector: 
> 
> https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2725
> https://bugs.wireshark.org/bugzilla/attachment.cgi?id=2029
> 
> it's  implemented the attack to CVE 2008 0166. This is basically a brute
> force against a relative small set of candidate private keys for the SSL
> session. 

Although not an answer to your question, I personally object to the
idea of putting brute force code into Wireshark. Wireshark has a good
reputation as a network analysis tool. Which of course means it can be
used for less honest purposes as well, but putting code in to deliberately
break security based on a weakness in the protocol crosses the line
for me. This would put Wireshark in a whole different set of tools
which might not do it good...

I personally vote against inclusing of this code into the source
tree. How do others feel about the inclussion of this code?

Cheers,
    Sake

  • Follow-Ups:
    • Re: [Wireshark-dev] performing cpu/time intensive computation in a protocol dissector
      • From: Ulf Lamping
    • Re: [Wireshark-dev] performing cpu/time intensive computation in a protocol dissector
      • From: Paolo Abeni
  • References:
    • [Wireshark-dev] performing cpu/time intensive computation in a protocol dissector
      • From: Paolo Abeni
  • Prev by Date: [Wireshark-dev] intense EP memory corruption checks
  • Next by Date: [Wireshark-dev] Field reg
  • Previous by thread: [Wireshark-dev] performing cpu/time intensive computation in a protocol dissector
  • Next by thread: Re: [Wireshark-dev] performing cpu/time intensive computation in a protocol dissector
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation