Web Hack List

Collected research

Exploiting padding oracles with fixed IVs

A session token is encrypted with AES-CBC but never signed and uses a fixed IV, so a padding oracle can forge chosen plaintext apart from one uncontrollable random block. Reusing the leading blocks of a freely issued anonymous token moves that junk inside a JSON string, and a second user property placed after it wins in JSON.parse, producing an admin token.

Record

Published by
Teddy Katz’s Blog
Date
Topic
Crypto

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Teddy Katz’s Blog, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .