oss-sec mailing list archives

Re: Truly scary SSL 3.0 vuln to be revealed soon:


From: ishish <ish () korrino com>
Date: Thu, 16 Oct 2014 08:37:43 +0000

Hanno Böck wrote:
It's out:

https://www.openssl.org/~bodo/ssl-poodle.pdf
http://googleonlinesecurity.blogspot.de/2014/10/this-poodle-bites-exploiting-ssl-30.html

My conclusion stays the same: Disable SSLv3.


Does anyone else see resemblance to chopchop attack?

-- 
ishish


Current thread: