Microsoft just released more info:

It turns out that this:

echo '30 1a 06 08 2b 06 01 04 01 82 37 12 01 01 ff 04 0b 16 09 54 4c
53 7e 42 41 53 49 43'|xxd -r -p|openssl asn1parse -dump -inform der
0:d=0 hl=2 l= 26 cons: SEQUENCE
2:d=1 hl=2 l= 8 prim: OBJECT : <-- a MS Terminal
Services licensing specific OID
12:d=1 hl=2 l= 1 prim: BOOLEAN :255  <-- "critical" attribute
15:d=1 hl=2 l= 11 prim: OCTET STRING
0000 - 16 09 54 4c 53 7e 42 41-53 49 43 ..TLS~BASIC

The fact that this custom OID was marked critical was in fact the sole reason that the attackers needed to do an MD5 collision at all.

- Marsh
cryptography mailing list

Reply via email to