Skip to Content
Advanced Infrastructure Penetration Testing
book

Advanced Infrastructure Penetration Testing

by Chiheb Chebbi
February 2018
Intermediate to advanced
396 pages
9h 38m
English
Packt Publishing
Content preview from Advanced Infrastructure Penetration Testing

POODLE attack (CVE-2014-3566) 

The Padding Oracle On Downgraded Legacy Encryption (POODLE) attack was discovered in 2014. This attack exploits the fact that many servers  support SSLv3 on one hand and a block padding vulnerability on the other hand. Following diagram demonstrates POODLE attack:

In general, as a first step, a client sends the supported TLS versions. In this case, the attacker intercepts the traffic performing a man-in-the-middle attack and mimics the server, until the connection is downgraded to SSLv3. If the connection is established, the attacker exploits a cipher block chaining vulnerability, by manipulating the padding ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Practical Web Penetration Testing

Practical Web Penetration Testing

Gus Khawaja
Securing Network Infrastructure

Securing Network Infrastructure

Sairam Jetty, Sagar Rahalkar

Publisher Resources

ISBN: 9781788624480Supplemental Content