The latest insights from the load balancing experts | Loadbalancer.org
  • Support
  • Blog
  • +1 833 274 2566
  • Solutions
  • Services
  • Products
  • Resources
  • Get Started
  • Support
  • Blog
Schedule your demo
  • Solutions
  • Services
  • Products
  • Resources
  • Get Started
  • Support
  • Blog

The latest insights from the load balancing experts | Loadbalancer.org

  • Latest posts
  • By topic
    • How Tos
    • Events
    • Guest Blogs
    • Top Ten Blogs
    • HA Proxy
  • By sector
    • Healthcare
    • Storage
    • Security
    • Print
    • Microsoft
  • How-To's
  • HAProxy
  • High Availability
  • Just for Fun
  • Security
  • Events
  • News
  • Linux
  • Top 10 Blogs
  • Amazon AWS
  • Reviews and Comparisons
  • Healthcare
  • SSL
  • Web Application Firewall (WAF)
  • Case Studies
  • Microsoft Azure
  • Disaster Recovery
  • Direct Server Return (DSR)
  • Global Server Load Balancing (GSLB)
  • Microsoft
  • Microsoft Exchange
  • Print
  • Denial of Service
  • Microsoft Remote Desktop Services
  • Object Storage
  • Web Filters / Proxy
  • Broadcast Media
  • X-Forwarded-For Header (XFF)
  • Guest Blogs
  • VMware
  • Google Cloud Platform (GCP)
  • Nutanix
See more tags

Not so sweet, Sweet32 vulnerability...

22 February 2017 / 1 min read / Security

It's a little bit late but I wanted to write a short entry about how to deal with the Sweet32 vulnerability which was announced towards the end of last year.  I'm going to avoid regurgitating all the various details and aspects relating to this vulnerability but more focus on how simple it is to mitigate it when using the SSL Termination/Offloading options available on a Loadbalancer.org appliance.  I am including a couple reference page links which delve into the nitty-gritty in significant detail if you wish/need/choose to further educate yourself on the subject.

When configuring SSL Termination/Offloading and using the default cipher list, a scan using SSL Labs will produce an A which is great.  One thing with our default list is that it could result in a scan indicating that there may be a vulnerability to Sweet32.  Sweet32 has several potential methods to be exploited but the one which potentially affects a Loadbalancer.org appliance is the use of the Triple-DES legacy cipher when performing SSL Termination/Offloading.
To mitigate this, it is a simple case of altering the cipher list slightly, adding a !3DES, to prevent the use of the Triple-DES cipher.

ECDHE-RSA-RC4-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:AES256-SHA:HIGH:!RC4:!MD5:!aNULL:!EDH

Should become:

ECDHE-RSA-RC4-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:AES256-SHA:HIGH:!3DES:!RC4:!MD5:!aNULL:!EDH

Having rescanned the SSL Labs tooling with the updated cipher list, we still get an A but now the Sweet32 vulnerability is also being prevented.

References:

  • https://sweet32.info/
  • https://www.openssl.org/blog/blog/2016/08/24/sweet32/
  • https://www.ssllabs.com/ssltest/index.html

Found in

Security

About the author

Dave Saunders-profile-image
Dave Saunders

Having previously worked as a system administrator at IBM for over 12 years, maintaining infrastructure used by a global team, Dave joined the Loadbalancer.org support team to further develop his skillset and gain experience of varied customer environments.

Read More

Related posts

HAProxy
HAProxy
27 Jul 2020
How to tackle bugs and vulnerabilities – a solutions architect’s opinion Himakshi Goswami
Dealing with bugs and vulnerabilities is quite common in the tech space. Aaron West, the head of Solutions at Loadbalancer.org shares some insights about our approach of tackling such issues, and more.

9 min read

Read more
Security
Security
18 Jun 2020
Healthcare IT should listen to Amazon's Werner Vogels: “Dance Like Nobody’s Watching. Encrypt Like Everyone Is” Aaron West
Find out why Werner Vogels' comments ring especially true for healthcare data.

5 min read

Read more
Healthcare
Healthcare
1 Mar 2017
DelftDI recommends Loadbalancer.org for load balancing critical medical imaging systems Jake Borman
DelftDI, a Canon group company, develops, delivers and maintains radiology and patient imaging systems for hospitals across the globe. For more than ten years, it has been recommending and installing products from Loadbalancer.org to

3 min read

Read more

Get started

Get in touch

Start a conversation about the right solution for your business.

Get in touch

Create your quote

Transparent pricing you can see straight away.

Create your quote

Download now

Try us free for 30 days – see why our customers love us.

Download now

Schedule a virtual meeting with us

Working remotely or from home? Let’s meet on a call or online.

Let's meet

Follow Loadbalancer.org

+1 833 274 2566
  • Company
    • Solutions
    • Services
    • Load balancer
    • Why Loadbalancer.org
    • Blog
    • Professional services
    • Sitemap
  • Load balancer
    • Get a quote
    • Free trial
    • Online demo
  • Resources
    • Manuals
    • Deployment guides
    • Applications
    • White papers
    • Case studies
    • Solutions
  • Support
    • FAQ's
    • Open a ticket
    • Security news
  • Applications
    • Healthcare
    • Storage
    • Print
    • Security
    • Microsoft
The latest insights from the load balancing experts | Loadbalancer.org

The latest insights from the load balancing experts | Loadbalancer.org. All rights reserved

  • Contact Us
  • Terms & Conditions
  • Privacy Policy