POET : Padding Oracle Exploit Tool

本文介绍了Padding Oracle攻击原理及其在网络安全领域的应用。通过利用该漏洞,攻击者可以在不知道共享密钥的情况下伪造有效的签名,进而代表任何使用Flickr API的应用程序发送任意请求。

Practical Padding Oracle Attacks

At Eurocrypt 2002, Vaudenay introduced a powerful side-channel attack, which is called padding oracle attack, against CBC-mode encryption. By giving an oracle which on receipt of a ciphertext, decrypting it and then replying to the sender whether the padding is correct or not, he shows that is possible to efficiently decrypt data without knowing the encryption key. In this paper, we turn the padding oracle attack into a new set of practical web hacking techniques.

Click this bar to view the full image.
53e5eb377b9224fa5c6f8ba8fd873ae2 POET : Padding Oracle Exploit Tool

Flickr offers a relatively comprehensive web-service API that allows programmers to build applications which could perform virtually any functionality a Flickr internet site can do. Users need to be authenticated while using Flickr Authentication API. Any applications wishing to use the Flickr Authentication API must have already obtained a Flickr’s API Key. An 8-byte extended ‘shared secret’ for ones API Key is then issued by Flickr and can not be changed by the users. This secret is applied during the signing process, that is certainly required for all API calls utilizing an authentication token. This advisory describes a vulnerability during the signing process that allows an attacker to build valid signatures with out knowing the shared secret. By exploiting this vulnerability, an attacker can send valid arbitrary requests on behalf of any computer software utilizing Flickr’s API

Download Padding Oracle Exploit Tool Here

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值