Web Hack List

Collected research

Exploiting The Not So Misuse-Resistant Authenticated Encryption API of OpenSSL

OpenSSL-backed AEAD decryption APIs in Ruby, PHP, Node.js, Rust and Erlang take the tag length from whatever tag is supplied, so code that never checks it accepts a one-byte tag, brute-forceable in 256 tries. An attacker can bit-flip GCM ciphertexts, decrypt them byte by byte with a format-validity oracle, and recover the GHASH key by nonce reuse to forge tags offline.

Record

Published by
sideni.xyz
Topic
Crypto

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of sideni.xyz, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .