Top 10 winner
Poodle
This POODLE Bites: Exploiting The SSL 3.0 Fallback
POODLE exploits SSL 3.0's unauthenticated CBC padding: an attacker who forces browsers down the version fallback dance can replace a ciphertext block and read the server's accept-or-reject answer as a padding oracle. About 256 requests per byte recover secure cookies, and the advisory proposes TLS_FALLBACK_SCSV to stop the downgrade.
Record
- Document
- This POODLE Bites: Exploiting The SSL 3.0 Fallback
- Researcher
- Bodo Möller, Thai Duong and Krzysztof Kotowicz
- Published by
- Format
- Whitepaper
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Bodo Möller, Thai Duong and Krzysztof Kotowicz, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .