Poodle – SSLv3 Vulnerability

In the space of a month, yet another security vulnerability has been identified and announced.

Known as the ‘SSLv3 protocol vulnerability and POODLE Attack’, (aka “POODLEbleed”, referencing the the recent Heartbleed vulnerability), the SSL Man In The Middle (MITM) Information Disclosure Vulnerability (CVE-2014-3566) affects version 3.0 of SSL, which was introduced in 1996, and has since been superseded by several newer versions of its successor protocol, TLS. However, the vulnerability may still be exploited because SSL 3.0 continues to be supported by nearly every Web browser and a large number of Web servers.

When web browsers fail at connecting on a newer SSL version (i.e. TLS 1.0, 1.1, or 1.2), they may fall back to a SSL 3.0 connection. Because a network attacker can cause connection failures, including the failure of TLS 1.0/1.1/1.2 connections, they can force the use of SSL 3.0 and then exploit the poodle bug in order to decrypt secure content transmitted between a server and a browser.

All systems and applications utilizing the Secure Socket Layer (SSL) 3.0 with cipher-block chaining (CBC) mode ciphers may be vulnerable. However, the POODLE (Padding Oracle On Downgraded Legacy Encryption) attack demonstrates this vulnerability using web browsers and web servers, which is one of the most likely exploitation scenarios.

On 26 September 2014, the Shellshock vulnerability affecting many versions of Linux and Unix, was announced.

Digital Tsunami hosts the websites of listed companies and multi-national corporations (MNCs) on their private clouds or international brands and national SMEs on private clouds which are exclusive to Digital Tsunami clients.

Security is uppermost in the priorities of Digital Tsunami and sites are constantly monitored and hardware and software maintained for maximum protection.

For enquiries on advanced security for your web presence, please contact Digital Tsunami Sales or Technical Support.

Read more items related to security.

 

External References:

Online Poodle Bug Server Test
Poodlebleed.com
Red Hat Security Advisory on POODLE
Symantec
Trend Micro
US Computer Emergency Readiness Team, Alert TA14-290A

From Our Clients

Quotation Mark

By taking the time to understand our business, industry and vision, Digital Tsunami created a site that truly reflected our leadership position in the market and our strategic direction.

Digital Tsunami's expertise in visual design, photography, website navigation and business writing, resulted in an extremely effective website.

The project was expertly managed from end to end which resulted in a fast and efficient process.

Robert Keiller
Finance Manager
Portland, Victoria, Australia
Quotation Mark

.. very knowledgeable, creative and patient while also pushing me to work through the many decisions such a project involves.

Corinna Sager
President
Montclair, New York, USA
Lifestyle International
Quotation Mark

Andrew helped us to see the potential of video in bringing our new website to life.

He held our hand through the process, making it as undaunting as possible.

He delivered a great selection of videos (from a one-day shoot), that really tell the Foodbank story and will be a great addition to our communications.

Sarah Pennell
Business and Communications Manager
Sydney, NSW, Australia
Foodbank Australia
Quotation Mark

I would like to thank you for your tremendous contribution to Foodbank over the years.

The organisation certainly wouldn’t be where we are today without your support!

Lyndon Pereira
Analysis & Design Co-ordinator
Sydney, Australia
Quotation Mark

Thank you for all your efforts in creating our new website which achieves our agreed objectives : elegantly smart, yet understated, professional and easy to use.

Terry A. Spinolo
Managing Director
Hong Kong
Inarc Design Asia Group
error: We appreciate that you value our content. You are welcome to link to this page, but content is copyright protected.