Later archive addition
ROBOT: Return Of Bleichenbacher's Oracle Threat
ROBOT revives Bleichenbacher's 1998 adaptive chosen-ciphertext attack on RSA PKCS #1 v1.5 by using new oracle signals such as timeouts, connection resets and duplicate alerts, and by truncating the TLS handshake. A vulnerable server can be used to decrypt recorded RSA-key-exchange traffic or to sign messages with its private key, as demonstrated against Facebook and PayPal.
Record
- Researcher
- Hanno Böck, Juraj Somorovsky and Craig Young
In the archive
Related sources
- USENIX paper and presentation
- RuhrSec recording
- BornHack recording
- USENIX recording
- Author’s detection tool
- Independent detector explanation
Tags
This page is the archive's own catalogue record. The research is the work of Hanno Böck, Juraj Somorovsky and Craig Young, first published at the original source. Preserved copies are kept so the citation survives its host.