Web Hack List

Collected research

How to Break XML Encryption

XML Encryption's CBC mode combined with the character encoding of the plaintext yields an oracle: a Web Service that rejects a message it cannot parse leaks whether a modified ciphertext decrypts to valid UTF-8. Jager and Somorovsky generalise padding-oracle attacks to recover plaintext at roughly 14 requests per byte, decrypting 160 bytes from Apache Axis2 in 10 seconds.

Record

Researcher
Tibor Jager and Juraj Somorovsky
Published by
nds.rub.de
Format
Whitepaper
Topic
Crypto

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Tibor Jager and Juraj Somorovsky, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .