Web Hack List

Other nomination

Exploiting The Not So Misuse-Resistant Authenticated Encryption API of OpenSSL

OpenSSL-backed AEAD decryption APIs in Ruby, PHP, Node.js, Rust and Erlang take the tag length from whatever tag is supplied, so code that never checks it accepts a one-byte tag, brute-forceable in 256 tries. An attacker can bit-flip GCM ciphertexts, decrypt them byte by byte with a format-validity oracle, and recover the GHASH key by nonce reuse to forge tags offline.

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.