Poodle Attack: Hackers Could Exploit SSL 3.0 Bug

Advertisement
By Reuters | Updated: 15 October 2014 09:15 IST
Three Google Inc researchers have uncovered a security bug in widely used web encryption technology that they say could allow hackers to steal data in what they have dubbed a "Poodle" attack.

"Poodle" stands for Padding Oracle On Downloaded Legacy Encryption.

The problem is an 18-year old encryption standard, known as SSL 3.0, which is still widely used in web browsers and websites. It was disclosed in a research paper published late on Tuesday on the website of the OpenSSL Project, a group that develops the most widely used type of SSL encryption software.

Rumors that a new bug in OpenSSL software had been circulating on Twitter and technology news sites in recent days, prompting some corporate security professionals to prepare to respond to a major new threat this week.

Advertisement

So far this year, they have responded to April's "Heartbleed" bug in OpenSSL, which affected an estimated two-thirds of all websites and thousands of other technology products, as well as last month's "Shellshock" bug in a piece of Unix software known as Bash.

Advertisement

But security experts said that the bug disclosed on Tuesday, which could allow hackers to steal browser "cookies," was not as serious as the two prior bugs.

"It's quite complicated. It requires the attacker to have a privileged position in the network," said Ivan Ristic, director of application security research with Qualys and an expert in SSL.

Advertisement

Jeff Moss, founder of the Def Con hacking conference and an advisor to the U.S. Department of Homeland Security, said that successful attackers could exploit the bug to steal session cookies in browsers, taking control of accounts for email providers, social networks and banks that use that technology.

To do that, however, they would need to launch a "man-in-the-middle" attack, placing themselves in between the victim and the websites they were visiting. One common approach is to create a rogue Wi-Fi "hot spot" in an Internet cafe, he said.

Advertisement

Matthew Green, assistant research professor at Johns Hopkins University's department of computer science, said this vulnerability was not as bad as either Heartbleed, which allowed hackers to snoop or steal large quantities of data, or Shellshock, which could give attackers remote control of computers.

He advised businesses and computer uses to disable SSL 3.0 technology on their servers and browsers, a process that he said can be difficult for the average computer user.

"It's not going to take out the infrastructure of the Internet. But it's going to be a hassle to fix," he said.

© Thomson Reuters 2014

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Announces Offers on Phones, Wearables During Flipkart Sale
  2. Vivo Y31 Series With 6,500mAh Battery Launched in India: See Price
  3. Samsung Begins Rolling Out One UI 8 Update to the Galaxy S25 Series
  4. [Exclusive] Noise to Launch Flagship Master Series Over-Ear Headphones Soon
  5. Flipkart Big Billion Days Sale: Discounts on Motorola Phones Announced
  6. Samsung Galaxy S25 FE With 50-Megapixel Camera Launched in India: See Price
  7. Samsung Galaxy S26 Ultra, Galaxy S26 Pro Charging Speed Leaked
  8. iOS 26 Update Brings These New Features to AirPods Pro 3, Pro 2, AirPods 4
  9. Samsung Galaxy S26 Series May Launch With This In-House Exynos Chip
  10. iOS 26 Released Alongside iPadOS 26, macOS Tahoe: Here's How to Download It
  1. Samsung Galaxy S26 Ultra, Galaxy S26 Pro Charging Speed Listed on Certification Website
  2. Apple's AirPods Pro 3, Pro 2, and AirPods 4 Get Firmware Update With New iOS 26 Features
  3. Samsung Galaxy S26 Series to Launch With In-House 2nm Exynos 2600 Chipset: Report
  4. Meta Ray-Ban Display With Heads-Up Display and sEMG Wristband Leaked Ahead of Meta Connect 2025
  5. The Witcher Season 4 Release Date Revealed: Know When and Where to Watch It Online
  6. iOS 26 Update Released Alongside iPadOS 26 and macOS Tahoe: Check Eligible Models, How to Download
  7. Scientists Propose Space Missions to Chase Down Interstellar Comets
  8. Iceland Plume Discovery Reveals Ancient Volcanic Funnels Across North Atlantic
  9. Huawei Watch Ultimate 2 Design Renders Leaked, Could Launch Soon
  10. Marvel's Wolverine Will Reportedly Launch in 2026; Insomniac's Venom Game in 'Active Development'
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.