| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -3,11 +3,15 @@ | |||
| 3 | 3 | "qhelp.dtd"> | |
| 4 | 4 | <qhelp> | |
| 5 | 5 | <overview> | |
| 6 | - <p>Using broken or weak cryptographic algorithms can leave data vulnerable to being decrypted.</p> | ||
| 7 | - | ||
| 8 | - <p>Many cryptographic algorithms provided by cryptography libraries are known to be weak, or | ||
| 9 | - flawed. Using such an algorithm means that an attacker may be able to easily decrypt the encrypted | ||
| 10 | - data.</p> | ||
| 6 | + <p>Using broken or weak cryptographic algorithms may compromise security guarantees such as confidentiality, integrity, and authenticity.</p> | ||
| 7 | + | ||
| 8 | + <p>Many cryptographic algorithms are known to be weak or flawed. The security guarantees of a system often rely on the underlying cryptography, so using a weak algorithm can have severe consequences. For example: | ||
| 9 | + </p> | ||
| 10 | + <ul> | ||
| 11 | + <li>If a weak encryption algorithm is used, an attacker may be able to decrypt sensitive data.</li> | ||
| 12 | + <li>If a weak hashing algorithm is used to protect data integrity, an attacker may be able to craft a malicious input that has the same hash as a benign one.</li> | ||
| 13 | + <li>If a weak algorithm is used for digital signatures, an attacker may be able to forge signatures and impersonate legitimate users.</li> | ||
| 14 | + </ul> | ||
| 11 | 15 | ||
| 12 | 16 | </overview> | |
| 13 | 17 | <recommendation> | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -3,11 +3,15 @@ | |||
| 3 | 3 | "qhelp.dtd"> | |
| 4 | 4 | <qhelp> | |
| 5 | 5 | <overview> | |
| 6 | - <p>Using broken or weak cryptographic algorithms can leave data vulnerable to being decrypted.</p> | ||
| 7 | - | ||
| 8 | - <p>Many cryptographic algorithms provided by cryptography libraries are known to be weak, or | ||
| 9 | - flawed. Using such an algorithm means that an attacker may be able to easily decrypt the encrypted | ||
| 10 | - data.</p> | ||
| 6 | + <p>Using broken or weak cryptographic algorithms may compromise security guarantees such as confidentiality, integrity, and authenticity.</p> | ||
| 7 | + | ||
| 8 | + <p>Many cryptographic algorithms are known to be weak or flawed. The security guarantees of a system often rely on the underlying cryptography, so using a weak algorithm can have severe consequences. For example: | ||
| 9 | + </p> | ||
| 10 | + <ul> | ||
| 11 | + <li>If a weak encryption algorithm is used, an attacker may be able to decrypt sensitive data.</li> | ||
| 12 | + <li>If a weak hashing algorithm is used to protect data integrity, an attacker may be able to craft a malicious input that has the same hash as a benign one.</li> | ||
| 13 | + <li>If a weak algorithm is used for digital signatures, an attacker may be able to forge signatures and impersonate legitimate users.</li> | ||
| 14 | + </ul> | ||
| 11 | 15 | ||
| 12 | 16 | </overview> | |
| 13 | 17 | <recommendation> | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -4,17 +4,34 @@ | |||
| 4 | 4 | <qhelp> | |
| 5 | 5 | <overview> | |
| 6 | 6 | <p> | |
| 7 | - Using broken or weak cryptographic algorithms can leave data | ||
| 8 | - vulnerable to being decrypted or forged by an attacker. | ||
| 7 | + Using broken or weak cryptographic algorithms may compromise | ||
| 8 | + security guarantees such as confidentiality, integrity, and | ||
| 9 | + authenticity. | ||
| 9 | 10 | </p> | |
| 10 | 11 | ||
| 11 | 12 | <p> | |
| 12 | - Many cryptographic algorithms provided by cryptography | ||
| 13 | - libraries are known to be weak, or flawed. Using such an | ||
| 14 | - algorithm means that encrypted or hashed data is less | ||
| 15 | - secure than it appears to be. | ||
| 13 | + Many cryptographic algorithms are known to be weak or flawed. The | ||
| 14 | + security guarantees of a system often rely on the underlying | ||
| 15 | + cryptography, so using a weak algorithm can have severe consequences. | ||
| 16 | + For example: | ||
| 16 | 17 | </p> | |
| 17 | 18 | ||
| 19 | + <ul> | ||
| 20 | + <li> | ||
| 21 | + If a weak encryption algorithm is used, an attacker may be able to | ||
| 22 | + decrypt sensitive data. | ||
| 23 | + </li> | ||
| 24 | + <li> | ||
| 25 | + If a weak hashing algorithm is used to protect data integrity, an | ||
| 26 | + attacker may be able to craft a malicious input that has the same | ||
| 27 | + hash as a benign one. | ||
| 28 | + </li> | ||
| 29 | + <li> | ||
| 30 | + If a weak algorithm is used for digital signatures, an attacker may | ||
| 31 | + be able to forge signatures and impersonate legitimate users. | ||
| 32 | + </li> | ||
| 33 | + </ul> | ||
| 34 | + | ||
| 18 | 35 | </overview> | |
| 19 | 36 | <recommendation> | |
| 20 | 37 | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -3,20 +3,33 @@ | |||
| 3 | 3 | "qhelp.dtd"> | |
| 4 | 4 | <qhelp> | |
| 5 | 5 | <overview> | |
| 6 | + | ||
| 6 | 7 | <p> | |
| 7 | - Using broken or weak cryptographic algorithms can leave data | ||
| 8 | - vulnerable to being decrypted or forged by an attacker. | ||
| 8 | + Using broken or weak cryptographic algorithms may compromise | ||
| 9 | + security guarantees such as confidentiality, integrity, and | ||
| 10 | + authenticity. | ||
| 9 | 11 | </p> | |
| 10 | 12 | ||
| 11 | 13 | <p> | |
| 12 | - Many cryptographic algorithms provided by cryptography | ||
| 13 | - libraries are known to be weak, or flawed. Using such an | ||
| 14 | - algorithm means that encrypted or hashed data is less | ||
| 15 | - secure than it appears to be. | ||
| 14 | + Many cryptographic algorithms are known to be weak or flawed. The | ||
| 15 | + security guarantees of a system often rely on the underlying | ||
| 16 | + cryptography, so using a weak algorithm can have severe consequences. | ||
| 17 | + For example: | ||
| 16 | 18 | </p> | |
| 17 | 19 | ||
| 20 | + <ul> | ||
| 21 | + <li> | ||
| 22 | + If a weak encryption algorithm is used, an attacker may be able to | ||
| 23 | + decrypt sensitive data. | ||
| 24 | + </li> | ||
| 25 | + <li> | ||
| 26 | + If a weak algorithm is used for digital signatures, an attacker may | ||
| 27 | + be able to forge signatures and impersonate legitimate users. | ||
| 28 | + </li> | ||
| 29 | + </ul> | ||
| 30 | + | ||
| 18 | 31 | <p> | |
| 19 | - This query alerts on any use of a weak cryptographic algorithm, that is | ||
| 32 | + This query alerts on any use of a weak cryptographic algorithm that is | ||
| 20 | 33 | not a hashing algorithm. Use of broken or weak cryptographic hash | |
| 21 | 34 | functions are handled by the | |
| 22 | 35 | <code>py/weak-sensitive-data-hashing</code> query. | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -4,14 +4,33 @@ | |||
| 4 | 4 | <qhelp> | |
| 5 | 5 | <overview> | |
| 6 | 6 | <p> | |
| 7 | - Using broken or weak cryptographic algorithms can leave data | ||
| 8 | - vulnerable to being decrypted or forged by an attacker. | ||
| 7 | + Using broken or weak cryptographic algorithms may compromise | ||
| 8 | + security guarantees such as confidentiality, integrity, and | ||
| 9 | + authenticity. | ||
| 9 | 10 | </p> | |
| 11 | + | ||
| 12 | + <p> | ||
| 13 | + Many cryptographic algorithms are known to be weak or flawed. The | ||
| 14 | + security guarantees of a system often rely on the underlying | ||
| 15 | + cryptography, so using a weak algorithm can have severe consequences. | ||
| 16 | + For example: | ||
| 17 | + </p> | ||
| 18 | + | ||
| 19 | + <ul> | ||
| 20 | + <li> | ||
| 21 | + If a weak encryption algorithm is used, an attacker may be able to | ||
| 22 | + decrypt sensitive data. | ||
| 23 | + </li> | ||
| 24 | + <li> | ||
| 25 | + If a weak algorithm is used for digital signatures, an attacker may | ||
| 26 | + be able to forge signatures and impersonate legitimate users. | ||
| 27 | + </li> | ||
| 28 | + </ul> | ||
| 10 | 29 | <p> | |
| 11 | - Many cryptographic algorithms provided by cryptography | ||
| 12 | - libraries are known to be weak, or flawed. Using such an | ||
| 13 | - algorithm means that encrypted or hashed data is less | ||
| 14 | - secure than it appears to be. | ||
| 30 | + This query alerts on any use of a weak cryptographic algorithm that is | ||
| 31 | + not a hashing algorithm. Use of broken or weak cryptographic hash | ||
| 32 | + functions are handled by the | ||
| 33 | + <code>rb/weak-sensitive-data-hashing</code> query. | ||
| 15 | 34 | </p> | |
| 16 | 35 | </overview> | |
| 17 | 36 | <recommendation> | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -3,20 +3,32 @@ | |||
| 3 | 3 | "qhelp.dtd"> | |
| 4 | 4 | <qhelp> | |
| 5 | 5 | <overview> | |
| 6 | - <p> | ||
| 7 | - Using broken or weak cryptographic algorithms can leave data | ||
| 8 | - vulnerable to being decrypted or forged by an attacker. | ||
| 9 | - </p> | ||
| 6 | + <p> | ||
| 7 | + Using broken or weak cryptographic algorithms may compromise | ||
| 8 | + security guarantees such as confidentiality, integrity, and | ||
| 9 | + authenticity. | ||
| 10 | + </p> | ||
| 10 | 11 | ||
| 11 | - <p> | ||
| 12 | - Many cryptographic algorithms provided by cryptography | ||
| 13 | - libraries are known to be weak, or flawed. Using such an | ||
| 14 | - algorithm means that encrypted or hashed data is less | ||
| 15 | - secure than it appears to be. | ||
| 16 | - </p> | ||
| 12 | + <p> | ||
| 13 | + Many cryptographic algorithms are known to be weak or flawed. The | ||
| 14 | + security guarantees of a system often rely on the underlying | ||
| 15 | + cryptography, so using a weak algorithm can have severe consequences. | ||
| 16 | + For example: | ||
| 17 | + </p> | ||
| 18 | + | ||
| 19 | + <ul> | ||
| 20 | + <li> | ||
| 21 | + If a weak encryption algorithm is used, an attacker may be able to | ||
| 22 | + decrypt sensitive data. | ||
| 23 | + </li> | ||
| 24 | + <li> | ||
| 25 | + If a weak algorithm is used for digital signatures, an attacker may | ||
| 26 | + be able to forge signatures and impersonate legitimate users. | ||
| 27 | + </li> | ||
| 28 | + </ul> | ||
| 17 | 29 | ||
| 18 | 30 | <p> | |
| 19 | - This query alerts on any use of a weak cryptographic algorithm, that is | ||
| 31 | + This query alerts on any use of a weak cryptographic algorithm that is | ||
| 20 | 32 | not a hashing algorithm. Use of broken or weak cryptographic hash | |
| 21 | 33 | functions are handled by the | |
| 22 | 34 | <code>rust/weak-sensitive-data-hashing</code> query. | |
| Back | FazBrowse Home | New Git URL |
0 commit comments