Poodle – SSLv3 VulnerabilityOctober 15, 2014
In the space of a month, yet another security vulnerability has been identified and announced.
Known as the ‘SSLv3 protocol vulnerability and POODLE Attack’, (aka “POODLEbleed”, referencing the the recent Heartbleed vulnerability), the SSL Man In The Middle (MITM) Information Disclosure Vulnerability (CVE-2014-3566) affects version 3.0 of SSL, which was introduced in 1996, and has since been superseded by several newer versions of its successor protocol, TLS. However, the vulnerability may still be exploited because SSL 3.0 continues to be supported by nearly every Web browser and a large number of Web servers.
When web browsers fail at connecting on a newer SSL version (i.e. TLS 1.0, 1.1, or 1.2), they may fall back to a SSL 3.0 connection. Because a network attacker can cause connection failures, including the failure of TLS 1.0/1.1/1.2 connections, they can force the use of SSL 3.0 and then exploit the poodle bug in order to decrypt secure content transmitted between a server and a browser.
All systems and applications utilizing the Secure Socket Layer (SSL) 3.0 with cipher-block chaining (CBC) mode ciphers may be vulnerable. However, the POODLE (Padding Oracle On Downgraded Legacy Encryption) attack demonstrates this vulnerability using web browsers and web servers, which is one of the most likely exploitation scenarios.
On 26 September 2014, the Shellshock vulnerability affecting many versions of Linux and Unix, was announced.
Digital Tsunami hosts the websites of listed companies and multi-national corporations (MNCs) on their private clouds or international brands and national SMEs on private clouds which are exclusive to Digital Tsunami clients.
Security is uppermost in the priorities of Digital Tsunami and sites are constantly monitored and hardware and software maintained for maximum protection.
For enquiries on advanced security for your web presence, please contact Digital Tsunami Sales or Technical Support.
From Our Clients
I am very happy with my new website from Digital Tsunami.
Not only did they design it, they also created my logo, and gave me valuable advice and professional feedback.
Through Digital Tsunami, my website now looks professional, easy to navigate and (through my customised CMS), easy to update.
We are all very happy with the new website and believe it captures the essence of the Group One brand.
Andrew and colleagues were able to assist at every step of the website production process, providing a sleek layout with high quality images. We would like to thank the Digital Tsunami team for an excellent job.
Digital Tsunami was professional, responsive and accurately interpreted our brief. The final result was a new website that was in keeping with the iBurst brand essence and proposition.
.. organised, meticulously detailed and yet flexible - always serving client needs to the highest standards. From a client perspective, you can expect high quality, timely completion and minimal fuss.
We are very pleased with the end result. It was good to have you pushing us along for material in order that we met the agreed completion deadline - you certainly are good project managers!