Web Hack List

Collected research

DROWN: Breaking TLS Using SSLv2

DROWN uses any server still speaking SSLv2 with the same RSA key as a Bleichenbacher padding oracle, letting a passive attacker decrypt recorded modern TLS sessions. An OpenSSL flaw present from 1998 to 2015 makes the cheap variant run in minutes on one machine, and a QUIC variant permits lasting server impersonation.

Record

Researcher
Nimrod Aviram, Sebastian Schinzel, Juraj Somorovsky, Nadia Heninger, Maik Dankel, Jens Steube, Luke Valenta, David Adrian, J. Alex Halderman, Viktor Dukhovni, Emilia Käsper, Shaanan Cohney, Susanne Engels, Christof Paar and Yuval Shavitt
Published by
usenix.org
Topic
Crypto

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Nimrod Aviram, Sebastian Schinzel, Juraj Somorovsky, Nadia Heninger, Maik Dankel, Jens Steube, Luke Valenta, David Adrian, J. Alex Halderman, Viktor Dukhovni, Emilia Käsper, Shaanan Cohney, Susanne Engels, Christof Paar and Yuval Shavitt, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .