Poodle – SSLv3 Vulnerability

In the space of a month, yet another security vulnerability has been identified and announced.

Known as the ‘SSLv3 protocol vulnerability and POODLE Attack’, (aka “POODLEbleed”, referencing the the recent Heartbleed vulnerability), the SSL Man In The Middle (MITM) Information Disclosure Vulnerability (CVE-2014-3566) affects version 3.0 of SSL, which was introduced in 1996, and has since been superseded by several newer versions of its successor protocol, TLS. However, the vulnerability may still be exploited because SSL 3.0 continues to be supported by nearly every Web browser and a large number of Web servers.

When web browsers fail at connecting on a newer SSL version (i.e. TLS 1.0, 1.1, or 1.2), they may fall back to a SSL 3.0 connection. Because a network attacker can cause connection failures, including the failure of TLS 1.0/1.1/1.2 connections, they can force the use of SSL 3.0 and then exploit the poodle bug in order to decrypt secure content transmitted between a server and a browser.

All systems and applications utilizing the Secure Socket Layer (SSL) 3.0 with cipher-block chaining (CBC) mode ciphers may be vulnerable. However, the POODLE (Padding Oracle On Downgraded Legacy Encryption) attack demonstrates this vulnerability using web browsers and web servers, which is one of the most likely exploitation scenarios.

On 26 September 2014, the Shellshock vulnerability affecting many versions of Linux and Unix, was announced.

Digital Tsunami hosts the websites of listed companies and multi-national corporations (MNCs) on their private clouds or international brands and national SMEs on private clouds which are exclusive to Digital Tsunami clients.

Security is uppermost in the priorities of Digital Tsunami and sites are constantly monitored and hardware and software maintained for maximum protection.

For enquiries on advanced security for your web presence, please contact Digital Tsunami Sales or Technical Support.

Read more items related to security.

 

External References:

Online Poodle Bug Server Test
Poodlebleed.com
Red Hat Security Advisory on POODLE
Symantec
Trend Micro
US Computer Emergency Readiness Team, Alert TA14-290A

From Our Clients

Quotation Mark

.. exceptional service and experience across all elements of web development from interactive strategy and marketing through to interface design and project management.

Peter Crocker
Owner
Sydney, NSW, Australia
BusinessCopywriter
Quotation Mark

Digital Tsunami’s work for Leighton International has been of an extremely high quality, highly responsive and flexible in approach. Andrew and his team worked with us to understand our needs and find the most appropriate solutions.

Keith Abbott
Group Manager, ODL
Abu Dhabi, United Arab Emirates
Leighton International
Quotation Mark

.. accurately interpreted the project brief and the outcome was a piece of cost effective quality work.

Lawrence Sank
Product Marketing Manager - Mobile Broadband
Sydney, NSW, Australia
Personal Broadband Australia
Quotation Mark

I happily recommend Andrew and the Digital Tsunami team.

I have dealt with many web marketing and support companies over the years, and have been very impressed with Digital Tsunami's response, advice and understanding of their field. I recommend talking to Andrew about your next web project.

Steve Peereboom
Brand Manager, Australian Monitor International
Melbourne, Victoria, Australia
Hills Holdings Ltd (ASX:HIL)
Quotation Mark

We are delighted with our new website and early feedback from clients and associates is very positive.

The overall impression is that it is a very professional, informative website and conveys the feeling that Sefiani is a quality organisation with skilled, friendly staff.

Thank you for all your help and patience in working with us for this successful outcome.

Robyn Sefiani
Managing Director
Sydney, NSW, Australia
Sefiani Communications Group
error: We appreciate that you value our content. You are welcome to link to this page, but content is copyright protected.