Collected research
ROBOT: Return Of Bleichenbacher's Oracle Threat
The ROBOT Attack
ROBOT revives Bleichenbacher's 1998 adaptive chosen-ciphertext attack on RSA PKCS #1 v1.5 by using new oracle signals such as timeouts, connection resets and duplicate alerts, and by truncating the TLS handshake. A vulnerable server can be used to decrypt recorded RSA-key-exchange traffic or to sign messages with its private key, as demonstrated against Facebook and PayPal.
Record
- Document
- The ROBOT Attack
- Researcher
- Hanno Böck, Juraj Somorovsky and Craig Young
- Published by
- robotattack.org
- Topic
- Other
In the archive
Related sources
- ROBOT
- ROBOT at RuhrSec 2018
- ROBOT at BornHack 2018
- ROBOT at USENIX Security 2018
- ROBOT detector
- SSLyze ROBOT detection
Tags
This page is the archive's own catalogue record. The research is the work of Hanno Böck, Juraj Somorovsky and Craig Young, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .