Skip to main content

POODLE Exploits SSL 3.0 Fallback - SC Magazine

October 15, 2014

POODLE Exploits SSL 3.0 Fallback - SC Magazine

SC Magazine, By Teri Robinson

Google researchers have uncovered a vulnerability in the design of the widely used SSL version 3.0 that allows an attacker to intercept plaintext data from secure connections, putting quite literally millions of browsers in jeopardy.

Researchers Bodo Möller, Thai Duong and Krzysztof Kotowicz created a Padding Oracle On Downgraded Legacy Encryption (POODLE) attack that exploited the flaw, which Kaspersky Lab security expert Sergey Lozhkin, said the vulnerability “allows an attacker to decrypt data transmitted between a user and a website if a vulnerable version of the protocol is in use.”

Since the protocol is so popular, exploitation of the vulnerability “could expose private data, but only if an attacker successfully performed a complicated Man-in-the-Middle (MitM) attack,” Lozhkin said in a statement emailed to SCMagazine.com. Read more.

POODLE Exploits SSL 3.0 Fallback - SC Magazine

POODLE Exploits SSL 3.0 Fallback - SC Magazine
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases