The DROWN Attack
drownattack.com
The DROWN Attack
1–10 of 206 posts
Re: The DROWN Attack
#2"In technical terms, DROWN is a new form of cross-protocol Bleichenbacher padding oracle attack. It allows an attacker to decrypt intercepted TLS connections by making specially crafted connections to an SSLv2 server that uses the same private key."
Re: The DROWN Attack
#3Re: The DROWN Attack
#4Re: The DROWN Attack
#5> To protect against DROWN, server operators need to ensure that their private keys are not used anywhere with server software that allows SSLv2 connections.
Also, I like this snippet:
> Disabling SSLv2 can be complicated and depends on the specific server software.
Re: The DROWN Attack
#6These marketed attacks with special logos drive me up the wall. If I ever discover one I'll give it a rude name and force everyone to look at a silly picture to go with it.
Re: The DROWN Attack
#7These marketed attacks with special logos drive me up the wall. If I ever discover one I'll give it a rude name and force everyone to look at a silly picture to go with it.
It gets worse, some people produce a whole video around it: https://www.youtube.com/watch?v=3NL2lEomB_Y
EDIT: Sorry, for consultancy read "peer-reviewed paper".
Re: The DROWN Attack
#8These marketed attacks with special logos drive me up the wall. If I ever discover one I'll give it a rude name and force everyone to look at a silly picture to go with it.
It gets worse, some people produce a whole video around it: https://www.youtube.com/watch?v=3NL2lEomB_Y
Re: The DROWN Attack
#9These marketed attacks with special logos drive me up the wall. If I ever discover one I'll give it a rude name and force everyone to look at a silly picture to go with it.
Re: The DROWN Attack
#10These marketed attacks with special logos drive me up the wall. If I ever discover one I'll give it a rude name and force everyone to look at a silly picture to go with it.
I'd be interested to know why this is the case. It's a hunch, but I reckon that this sort of 'branding' makes a serious problem more obvious and memorable. I mean, I remember 'Heartbleed' and 'GHOST', but I don't really remember the details of say CVE-2014-2523.