KB / Глосарій / Оракул відступу

Оракул відступу

Padding Oracle Attack
Також: CBC Padding Oracle, POODLE
crypto UA EN

Padding Oracle Attack exploits a CBC-mode block cipher when a server (the oracle) reveals whether padding is valid.

Allows decryption or forgery without the key (~128 requests/byte).

Mitigations

Authenticated encryption (AES-GCM), constant-time padding validation, Encrypt-then-MAC.

Вперше тут?
Новачок на Bastion?
Почни з гайду користувача.
Відкрити гайд →
?