FREE Registration is required
Overview:
Simple password authentication is often used e.g. from an email software application to a remote IMAP server. This is frequently done in a protected peer-to-peer tunnel, e.g. by SSL/TLS. At Eurocrypt'02, Vaudenay presented vulnerabilities in padding schemes used for block ciphers in CBC mode. He used a side channel, namely error information in the padding verification. This attack was not possible against SSL/TLS due to both unavailability of the side channel (errors are encrypted) and premature abortion of the session in case of errors. This paper extends the attack and optimizes it. The paper shows it is actually applicable against latest and most popular implementations of SSL/TLS (at the time this paper was written) for password interception.
(Is this item miscategorized? Does it need more tags? Let us know.)
| Format: | Size: | 162 KB | |
| Date: | Jan 2009 | ||
| Pages: | 17 |
Top results from SSL - TLS
Top results from Security Management
White Papers, Webcasts, and Resources
- Live Webcast: Get Control over SaaS Application Access TriCipherLearn to simplify and protect access to your company's data in Software-as-a-Service (SaaS) apps using identity and access management best practices.
- The Essential Guide: Real-Time High Availability for Exchange - Replicate Exchange Data for Improved Resiliency CA XOsoftSurvive major interruptions to your Exchange environment--and improve its resiliency and availability--with a real-time data replication solution.
- Accelerating Secure Business Applications Podcast RiverbedHear about new WAN acceleration techniques that can bring dramatic performance gains to your SSL-encrypted applications.
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
Featured Training Courses
Meet Doc
-
Here to help you with your Document Management Needs
- Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
- To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
-
Produced by
ZDNet and







