Ars Technica reports on a vulnerability where unencrypted Network Time Protocol (NTP) traffic can be exploited by man-in-the-middle attacks to arbitrarily set the times of computers to cause general chaos and/or carry out other attacks, such as exploiting expired HTTPS certificates.
While NTP clients have features to prevent drastic time changes, such as setting the date to ten years in the past, the paper on the attacks presents various methods for bypassing these protections.
There is a pdf of the report available.
(Score: 2) by Gaaark on Friday October 23 2015, @01:35AM
"Heck ya! It's 5 o'drunk somewhere, amiright?"
--- Please remind me if I haven't been civil to you: I'm channeling MDC. ---Gaaark 2.0 ---