Offpath Attacks Against PKI

No ratings

Presented at DeepSecVienna 2018 by

The security of Internet-based applications fundamentally rely on the trustworthiness of Certificate Authorities (CAs). We practically demonstrate for the first time that even a very weak off-path attacker can effectively subvert the trustworthiness of popular and commercially used CAs. Our attack targets CAs which use Domain Validation (DV) for authenticating domain ownership; collectively these CAs control 99% of the certificate market. The attack exploits DNS cache poisoning and tricks the CA into issuing fraudulent certificates for domains that the attacker does not own. Namely, certificates binding the attacker’s public key to victim domain.Our work is the first to weaponise DNS cache poisoning and to apply it to circumvent security of a critical PKI system.