Web Hack List

Later archive addition

Revisiting SSL/TLS Implementations: New Bleichenbacher Side Channels and Attacks

Four new Bleichenbacher oracles in the TLS RSA handshake: a JSSE error-message difference, OpenSSL timing, Java exception-handling timing, and a Cavium NITROX chip that leaks whether decrypted data starts 0x?? 02. Three are practical over a switched network, letting an attacker decrypt a recorded PreMasterSecret and with it the whole session.

Record

Researcher
Christopher Meyer, Juraj Somorovsky, Eugen Weiss, Jörg Schwenk, Sebastian Schinzel and Erik Tews

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Christopher Meyer, Juraj Somorovsky, Eugen Weiss, Jörg Schwenk, Sebastian Schinzel and Erik Tews, first published at the original source. Preserved copies are kept so the citation survives its host.