Google Online Security Blog: This POODLE bites: exploiting the SSL 3.0 fallback

Header The latest news and insights from Google on security and safety on the Internet all content wrapper start This POODLE bites: exploiting the SSL 3.0 fallback Posted: Tuesday, October 14, 2014 Tweet Today we are publishing details of a vulnerability in the design of SSL version 3.0. This vulnerability allows the plaintext of secure connections to be calculated by a network attacker. I discovered this issue in collaboration with Thai Duong and Krzysztof Kotowicz (also Googlers). SSL 3.0 is nearly 15 years old, but support for it remains widespread. Most importantly, nearly all browsers support it and, in order to work around bugs in HTTPS servers, browsers will retry failed connections with older protocol versions, including SSL 3.0. Because a network attacker can cause connection failures, they can trigger the use of SSL 3.0 and then exploit ...

Linked on 2014-10-14 23:46:11 | Similar Links