Return Of Bleichenbacher's Oracle Threat (ROBOT)
Hanno Böck, Juraj Somorovsky, Craig Young
摘要
In 1998 Bleichenbacher presented an adaptive chosenciphertext attack on the RSA PKCS #1 v1.5 padding scheme. The attack exploits the availability of a server which responds with different messages based on the ciphertext validity. This server is used as an oracle and allows the attacker to decrypt RSA ciphertexts. Given the importance of this attack, countermeasures were defined in TLS and other cryptographic standards using RSA PKCS #1 v1.5. We perform the first large-scale evaluation of Bleichenbacher's RSA vulnerability. We show that this vulnerability is still very prevalent in the Internet and affected almost a third of the top 100 domains in the Alexa Top 1 Million list, including Facebook and Paypal. We identified vulnerable products from nine different vendors and open source projects, among them F5, Citrix, Radware, Palo Alto Networks, IBM, and Cisco. These implementations provide novel side-channels for constructing Bleichenbacher oracles: TCP resets, TCP timeouts, or duplicated alert messages. In order to prove the importance of this attack, we have demonstrated practical exploitation by signing a message with the private key of facebook.com's HTTPS certificate. Finally, we discuss countermeasures against Bleichenbacher attacks in TLS and recommend to deprecate the RSA encryption key exchange in TLS and the RSA PKCS #1 v1.5 standard.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper24
- The 9 Lives of Bleichenbacher's CAT: New Cache ATtacks on TLS ImplementationsEyal Ronen, Robert Gillham, Daniel Genkin, Adi Shamir 等S&P 2019 · 被引用 59 次
- The Dangers of Key Reuse: Practical Attacks on IPsec IKEDennis Felsch, Martin Grothe, Jörg Schwenk, Adam Czubak 等USENIX Security 2018 · 被引用 41 次
- Raccoon Attack: Finding and Exploiting Most-Significant-Bit-Oracles in TLS-DH(E)Robert Merget, Marcus Brinkmann, Nimrod Aviram, Juraj Somorovsky 等USENIX Security 2021 · 被引用 36 次
- Scalable Scanning and Automatic Classification of TLS Padding Oracle VulnerabilitiesRobert Merget, Juraj Somorovsky, Nimrod Aviram, Craig Young 等USENIX Security 2019 · 被引用 27 次
- DY Fuzzing: Formal Dolev-Yao Models Meet Cryptographic Protocol Fuzz TestingMax Ammann, Lucca Hirschi, Steve KremerS&P 2024 · 被引用 25 次
它引用的顶会 Paper2
相关 Paper
- Windows into the Past: Exploiting Legacy Crypto in Modern OS's Kerberos ImplementationMichal Shagam, Eyal RonenUSENIX Security 2024
- Morpheus: Bringing The (PKCS) One To Meet the OracleMoosa Yahyazadeh, Sze Yiu Chau, Li Li, Man Hong Hue 等CCS 2021 · 被引用 5 次
- Open to a fault: On the passive compromise of TLS keys via transient errorsGeorge Arnold Sullivan, Jackson Sippe, Nadia Heninger, Eric WustrowUSENIX Security 2022
- "Make Sure DSA Signing Exponentiations Really are Constant-Time"Cesar Pereida García, Billy Bob Brumley, Yuval YaromCCS 2016 · 被引用 93 次
- Towards Internet-Based State Learning of TLS State MachinesMarcel Maehren, Nurullah Erinola, Robert Merget, Jörg Schwenk 等USENIX Security 2025
