4 ms·
http://archiv.infsec.ethz.ch/education/fs08/secsem/Bleichenbacher98.pdf http://archiv.infsec.ethz.ch/education/fs08/secsem/Bleichenb...
by dfranke 15y ago
http://archiv.infsec.ethz.ch/education/fs08/secsem/Bleichenbacher98.pdf http://archiv.infsec.ethz.ch/education/fs08/secsem/Bleichenb...
- agl 15y agoThis was actually a different attack on RSA by the same person! tptacek described the padding attack well in a sibling comment.
- NateLawson 15y agoBleichenbacher often comes out of hiding and posts some terrible crypto bug, usually based on a slight implementation deviation from best practices. The above bug is in RSA encryption, not signing, and is much more interesting technically than the e=3 padding verification bug. Just by revealing a different error message, attackers can use your server as a decryption oracle. It's different than the POET/BEAST attacks though, which are on block cipher modes. I tried to write a clear review of the paper here: http://rdist.root.org/2008/01/07/ssl-pkcs-padding-attack/ http://rdist.root.org/2008/01/07/ssl-pkcs-padding-attack/ The amusing thing is that he usually picks a random toolkit you've never heard of to attack, and then someone else (Hal Finney in the case of the e=3 padding bug) realizes it's a widespread issue in much more important systems.