• News
  • Security
  • Products
  • About Seqrite
Blogs on Information Technology, Network & Cybersecurity | Seqrite Blog
  • News
  • Security
  • Products
  • About Seqrite
Home  /  News • Security  /  Logjam Vulnerability: Why You Need to Upgrade Your Browsers
Logjam Vulnerability: Why You Need to Upgrade Your Browsers
29 January 2016

Logjam Vulnerability: Why You Need to Upgrade Your Browsers

Written by Rahul Thadani
Rahul Thadani
News, Security

Original Post – May 21, 2015

Another new SSL (Secure Sockets Layer) vulnerability has come to light in the last few hours and your home computers and office workstations could be at risk. If you are familiar with the Heartbleedand FREAK attacks from the last few months, then you would know that such kind of vulnerabilities cannot be taken lightly.

This new vulnerability is called “Logjam” and it affects simple protocols that the Internet is based on. Basically, whenever two sites need to exchange confidential information they also exchange a set of cryptographic keys in a secure manner. These keys help them decode the information that they receive. This exchange is carried out by the “Diffie-Hellman key exchange (D-H)” method. What the Logjam attack does is intercept this algorithm and prevents sites from sharing these keys with each other.

An attacker can instigate a Man-in-the-Middle (MITM) attack to downgrade a TLS connection to an inferior version and then steal sensitive information. This methodology bears several similarities to the recent FREAK attack as well.

How was the Logjam vulnerability discovered?

This vulnerability was discovered by a group of security researchers from Johns Hopkins University, University of Michigan, University of Pennsylvania, Microsoft Research, CNRS, Inria Nancy-Grand Est, and Inria Paris-Rocquencourt.

They have published more details and a technical report about the Logjam vulnerability which can be viewed over here. You can also check if your browser is vulnerable by visiting this link.

Who is vulnerable to the Logjam vulnerability?

Pretty much anyone who uses the Internet is potentially at risk here. This includes websites, mail servers and other TLS (Transport Layer Security) dependent services. The report further states that about 8.4% of the top 1 million domains are vulnerable – a number that roughly translates to around 84,000 domains. This security vulnerability can be especially dangerous for services that require personal user credentials and facilitate the transfer of sensitive information.

What this also means is that business enterprises who conduct operations online are also at risk. Data that is transferred through their various channels can theoretically be intercepted and stolen. As a result, enterprises need to take immediate steps to prevent this threat.

In their report, the researchers also speculate that “a close reading of published NSA leaks shows that the agency’s attacks on VPNs are consistent with having achieved such a break.” However, whether the NSA has actually used Logjam to intercept data merely remains speculation as of now.

What can be done to prevent such attacks?

The best solution to the Logjam vulnerability right now is to update all your browsers and programs immediately. All browser providers such as Google, Mozilla, Microsoft, Apple and others are working on fixing this vulnerability. So you regularly need to check for browser updates for your home or business machines. Moreover, if you are running a mail or web server, you need to disable support for export cipher suites and also generate a unique 2048-bit Diffie-Hellman group.

 Previous PostAlert: Ransomware Infections on the Rise
Next Post  How Vulnerable is your Small and Medium-sized Business?
Rahul Thadani

About Rahul Thadani

Rahul is a web enthusiast and blogger, and has been writing about the computer security industry for the last three years. Following the latest technology trends,...

Articles by Rahul Thadani »

Related Posts

  • data privacy

    The What, How, and Why of Data Privacy

    January 24, 2025
  • How the Recent Health Insurance Data Breach Could Affect You – and What You Can Do About It

    October 14, 2024
  • Defending against APT attacks with endpoint security

    How To Defend Against Advanced Persistent Threats (APTs): A Comprehensive Approach

    September 27, 2024
Featured Authors
  • Seqrite
    Seqrite

    Follow us for the latest updates and insights related to security for...

    Read more..
  • Sanjay Katkar
    Sanjay Katkar

    Sanjay Katkar is the Joint Managing Director of Quick Heal Technologies...

    Read more..
  • Mahua Chakrabarthy
    Mahua Chakrabarthy

    A tea connoisseur who firmly believes that life is too short for dull content....

    Read more..
Topics
apt (19) Cyber-attack (35) cyber-attacks (58) cyberattack (16) cyberattacks (13) Cybersecurity (322) cyber security (31) Cyber threat (33) cyber threats (48) Data (11) data breach (55) data breaches (28) data loss (28) data loss prevention (34) data privacy (11) data protection (24) data security (15) DLP (49) Encryption (16) endpoint security (107) Enterprise security (17) Exploit (14) firewall (11) GDPR (12) hackers (11) malware (76) malware attack (23) malware attacks (12) MDM (25) Microsoft (15) Network security (22) Patch Management (12) phishing (27) Ransomware (67) ransomware attack (30) ransomware attacks (30) ransomware protection (13) security (11) Seqrite (33) Seqrite Encryption (27) Seqrite EPS (33) Seqrite Services (16) UTM (34) Vulnerability (16) windows (11)
Loading
Resources
  • White Papers
  • Datasheets
  • Threat Reports
  • Manuals
  • Case Studies
About Us
  • About Seqrite
  • Leadership
  • Awards & Certifications
  • Newsroom
Archives
  • By Date
  • By Category
Loading

© 2025 Quick Heal Technologies Ltd. Cookie Policies Privacy Policies