Poodle Attack: Hackers Could Exploit SSL 3.0 Bug

Advertisement
By Reuters | Updated: 15 October 2014 09:15 IST
Three Google Inc researchers have uncovered a security bug in widely used web encryption technology that they say could allow hackers to steal data in what they have dubbed a "Poodle" attack.

"Poodle" stands for Padding Oracle On Downloaded Legacy Encryption.

The problem is an 18-year old encryption standard, known as SSL 3.0, which is still widely used in web browsers and websites. It was disclosed in a research paper published late on Tuesday on the website of the OpenSSL Project, a group that develops the most widely used type of SSL encryption software.

Advertisement

Rumors that a new bug in OpenSSL software had been circulating on Twitter and technology news sites in recent days, prompting some corporate security professionals to prepare to respond to a major new threat this week.

So far this year, they have responded to April's "Heartbleed" bug in OpenSSL, which affected an estimated two-thirds of all websites and thousands of other technology products, as well as last month's "Shellshock" bug in a piece of Unix software known as Bash.

Advertisement

But security experts said that the bug disclosed on Tuesday, which could allow hackers to steal browser "cookies," was not as serious as the two prior bugs.

"It's quite complicated. It requires the attacker to have a privileged position in the network," said Ivan Ristic, director of application security research with Qualys and an expert in SSL.

Advertisement

Jeff Moss, founder of the Def Con hacking conference and an advisor to the U.S. Department of Homeland Security, said that successful attackers could exploit the bug to steal session cookies in browsers, taking control of accounts for email providers, social networks and banks that use that technology.

To do that, however, they would need to launch a "man-in-the-middle" attack, placing themselves in between the victim and the websites they were visiting. One common approach is to create a rogue Wi-Fi "hot spot" in an Internet cafe, he said.

Advertisement

Matthew Green, assistant research professor at Johns Hopkins University's department of computer science, said this vulnerability was not as bad as either Heartbleed, which allowed hackers to snoop or steal large quantities of data, or Shellshock, which could give attackers remote control of computers.

He advised businesses and computer uses to disable SSL 3.0 technology on their servers and browsers, a process that he said can be difficult for the average computer user.

"It's not going to take out the infrastructure of the Internet. But it's going to be a hassle to fix," he said.

© Thomson Reuters 2014

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Moto Pad 70 Pro With a 10,200mAh Battery Debuts in India at This Price
  2. These iPhone Models Will Be Discounted During the Flipkart Sale
  3. These Upcoming OnePlus Phones Could Arrive With 185Hz Displays for Gamers
  4. This is When Apple Could Launch the iPhone 18 Pro and iPhone 18 Pro Max
  5. Samsung Might Launch Its First Commercial Rollable Phone in 2028
  1. Red Magic Astra 2 Confirmed to Debut as Global Variant of Upcoming Red Magic Gaming Tablet 5 Pro
  2. Vivo X500 Series Tipped to Feature Four Models; Vivo X500 Pro Max Said to Feature LPDDR6 RAM
  3. Bitcoin Holds Near $60,000 as Geopolitical Tensions Keep Crypto Investors on Edge
  4. PS6 Tipped to Cost Nearly $1,000 to Manufacture as Memory Prices Continue to Rise
  5. Vivo TWS 5 Pro Launched With Built-In Hi-Fi DAC, Up to 50 Hours of Total Battery Life: Price, Features
  6. Samsung Reportedly Developing Rollable Phone With Expandable 10-Inch Display
  7. Xiaomi 18 Tipped to Feature 7,200mAh Battery Despite Its Compact Form Factor
  8. Grand Theft Auto 6 Will Reportedly Not Get a Disc Version After November Launch
  9. Moto Pad 70 Pro Launched in India With 10,200mAh Battery, 13-Inch 3.5K Display: Price, Specifications
  10. Apple Smart Glasses Said to Launch by End of 2027 as Rival to Meta's Smart Glasses
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.