Browser Exploit Against SSL/TLS or BEAST is an attack that exploits a well known vulnerability on Chipher-block Chaining (CBC) mode encryption algorithms (such as AES and 3DES) which affects SSL and TLS v1.0.
BEAST consists of a network sniffer and Javascript/applet agents. It typically attacks SSL in the Client's browsers and not on the Server side's SSL. Once the BEAST agent has been successfully loaded into a client's browser, it wil decrypt all the client's cookies byte by byte. It speeds up the process by predicting known cookie names and stops when it gets the Session Identifier cookies. With the Session Identifier cookies, the attacker will be able to access the victim's secured online accounts.
FortiWeb MR4 and above
# config system advanced # set prioritize-rc4-cipher-suite {enable|disable} # end |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.