December 8, 2017

SSL/TLS Attacks

Padding oracles in CBC mode Compression

  • Vaudenay 2002
  • Boneh/Brumley 2003
  • BEAST 2011
  • Lucky13 2013
  • POODLE 2014
  • Lucky Microseconds 2015

RSA PKCS1-1.5

  • Bleichenbacher 1998
  • Jager 2015
  • DROWN 2016

MD5 & SHA1

  • CA forgery attack 2008
  • SLOTH 2016

Compression

  • CRIME 2012
  • BREACH 2013

Renegotiation

  • Marsh Ray Attack 2009
  • Renegotiation DoS 2011
  • 3Shake 2014

Export-grade ciphers

  • FREAK 2014
  • LogJam and WeakDH 2015
  • Sweet32 2016

Other

  • RC4 2013
  • Nonce reuse 2016

No comments: