Comum · História
Padding oracle attack
Attack which uses the padding validation of a cryptographic message to decrypt the ciphertext
In cryptography, a padding oracle attack is an attack which uses the padding validation of a cryptographic message to decrypt the ciphertext. In cryptography, variable-length plaintext messages often have to be padded (expanded) to be compatible with the underlying cryptographic primitive.
Na Wikipédia
Texto em inglês Ainda não há artigo no seu idioma: trecho em inglês.
In cryptography, a padding oracle attack is an attack which uses the padding validation of a cryptographic message to decrypt the ciphertext. In cryptography, variable-length plaintext messages often have to be padded (expanded) to be compatible with the underlying cryptographic primitive. The attack relies on having a "padding oracle" which freely responds to queries about whether a message is correctly padded or not. The information could be directly given, or leaked through a side-channel. The earliest well-known attack that uses a padding oracle is Bleichenbacher's attack of 1998, which attacks RSA with PKCS #1 v1.5 padding. The term "padding oracle" appeared in literature in 2002, after Serge Vaudenay's attack on the CBC mode decryption used within symmetric block ciphers. Variants of both attacks continue to find success more than one decade after their original publication.
Texto: Wikipédia em inglês, CC BY-SA 4.0. ·
Cartas próximas
-
T★
Tamanho da chave
-
★★★
3DES
-
★★★
Ataque man-in-the-middle
-
K★
Known-plaintext attack
Cryptanalytic attack model where the attacker has access to both the plaintext and its encrypted version
-
★★★
Morris worm
-
A★
Ataque da preimagem
-
A★
Attack vector
Method which malicious code utilizes to infect a computer or propagates itself
-
★
DES-X
-
C★★
CryptoLocker
Malware
-
★★
Data Encryption Standard
-
O★
Off-the-Record Messaging
-
T★★★
Teste de intrusão
-
★★
IDN homograph attack
Using visually similar characters in domain names to deceive users
-
O★
Operation Aurora
Series of cyberattacks conducted by Chinese threat actors
-
A★
Attack surface
Vulnerable software environment where an unauthorized user can utilize as starting point to alter or extract data
-
A★
Ataque de cifrotexto conhecido
-
★
CBC-MAC
-
★★
RC4