2.2 Implants: Types, Ways of Injection, and Methods of Protection
139
As we can see, the second if operator is followed with two goto fail strings,
and the second string is always implemented regardless of the result of if. Thus,
the certification verification procedure is not complete. An intruder familiar with
this vulnerability can easily forge a certificate and pass the authenticity verification.
This will help the intruder to organize a “man-in-the-middle” attack, interrupting
the secure connection between the client and the server. The researchers who have
discovered this error in implementation cannot say whether it was made accidentally
or on purpose. It can very well be a backdoor built into the algorithm by one of the
developers.
Specially Selected Constants
Many modern cryptographic algorithms use a certain set of internal constants in
their operation. As a rule, these constants are set by the standard and chosen based
on considerations of cryptographic resistance to currently known types of cryptoanalysis. However, selection of constants during standardization of an algorithm can
theoretically be used by developers with malicious intent—for example, to create
certain vulnerabilities and backdoors in the algorithm. To exemplify such use of
constants, we can cite the studies dedicated to the so-called malicious hashing, in
which the authors managed to build collisions for the SHA1 cryptographic hash function by modifying its round constants. It should be noted that the attack suggested by
the authors of the study is not aimed at the SHA1 hash function itself; it only helps
find collisions on condition of the possibility of changing round constants and only
for certain file types.
SHA1 overview:
SHA1 is a modern round hash function. The hashing algorithm is as follows:
– The following 32-bit values are initiated: a = h0, b = hv c = h2, d = h3, e = h4;
– The input message is divided into 512-bit blocks;
– Each message block is processed and supplemented in a special way according
to the algorithm defined in the standard;
139
As we can see, the second if operator is followed with two goto fail strings,
and the second string is always implemented regardless of the result of if. Thus,
the certification verification procedure is not complete. An intruder familiar with
this vulnerability can easily forge a certificate and pass the authenticity verification.
This will help the intruder to organize a “man-in-the-middle” attack, interrupting
the secure connection between the client and the server. The researchers who have
discovered this error in implementation cannot say whether it was made accidentally
or on purpose. It can very well be a backdoor built into the algorithm by one of the
developers.
Specially Selected Constants
Many modern cryptographic algorithms use a certain set of internal constants in
their operation. As a rule, these constants are set by the standard and chosen based
on considerations of cryptographic resistance to currently known types of cryptoanalysis. However, selection of constants during standardization of an algorithm can
theoretically be used by developers with malicious intent—for example, to create
certain vulnerabilities and backdoors in the algorithm. To exemplify such use of
constants, we can cite the studies dedicated to the so-called malicious hashing, in
which the authors managed to build collisions for the SHA1 cryptographic hash function by modifying its round constants. It should be noted that the attack suggested by
the authors of the study is not aimed at the SHA1 hash function itself; it only helps
find collisions on condition of the possibility of changing round constants and only
for certain file types.
SHA1 overview:
SHA1 is a modern round hash function. The hashing algorithm is as follows:
– The following 32-bit values are initiated: a = h0, b = hv c = h2, d = h3, e = h4;
– The input message is divided into 512-bit blocks;
– Each message block is processed and supplemented in a special way according
to the algorithm defined in the standard;
