| 
 | |||||||
|  | 
|  | Thread Tools | Search this Thread | 
|  10-29-2014, 05:53 PM | #1 | ||
| Treachery of images ...            Posts: 4,149 Karma: 94320195 Join Date: May 2012 Location: Australia Device: Sony 650, Kobo Glo, H2O, Aura One, Forma, Libra 2, Libra Colour | 
				
				poodle - Padding Oracle On Downgraded Legacy Encryption SSL vulnerability
			 
			
			POODLE (Padding Oracle On Downgraded Legacy Encryption) SSL vulnerability - seems we have to be worried about poodles now.   I confess to not really understanding much about this, but I'm sure that others on this forum will. Hereunder is some basic info and links. (And a big thank you to bookmarked in the Kobo Discounts thread who brought poodle to our attention  ) Here's what Mozilla says: Quote: 
 From http://www.theregister.co.uk/2014/10..._fixit_for_ie/ Quote: 
 ------------------ Apple said Wednesday it will stop supporting the encryption standard Secure Sockets Layer 3.0 for its push notifications service in response to a vulnerability identified earlier this month in the aging protocol. Spoiler: 
 A site that tests your browser for vulnerability issues: https://www.poodletest.com/ (And yep mine was vulnerable when I tested it, so I downloaded the Mozilla fix and now it's not) Last edited by Lynx-lynx; 10-29-2014 at 06:50 PM. Reason: add the word 'be' in the first sentence | ||
|   |   | 
|  10-29-2014, 09:03 PM | #2 | |
| Addict            Posts: 219 Karma: 1000210 Join Date: Mar 2014 Device: Kobo | Quote: 
 My results: Firefox 33.0.2 is not vulnerable. Internet Explorer 11 is vulnerable. | |
|   |   | 
| Advert | |
|  | 
|  10-29-2014, 09:11 PM | #3 | 
| Ex-Helpdesk Junkie            Posts: 19,421 Karma: 85400180 Join Date: Nov 2012 Location: The Beaten Path, USA, Roundworld, This Side of Infinity Device: Kindle Touch fw5.3.7 (Wifi only) | 
			
			FF 33.0.2 is vulnerable, Mozilla will disable SSLv3.0 in FF34.
		 | 
|   |   | 
|  10-29-2014, 10:08 PM | #4 | 
| Treachery of images ...            Posts: 4,149 Karma: 94320195 Join Date: May 2012 Location: Australia Device: Sony 650, Kobo Glo, H2O, Aura One, Forma, Libra 2, Libra Colour | 
			
			How does one know if they've been affected by this vulnerability, I'm a bit confused ....    | 
|   |   | 
|  10-29-2014, 10:34 PM | #5 | |
| Addict            Posts: 219 Karma: 1000210 Join Date: Mar 2014 Device: Kobo | Quote: 
 https://blog.mozilla.org/security/20...nd-of-ssl-3-0/ But when I run poodletest.com, the results are not vulnerable for Firefox 33.0.2. Poodletest.com reported "your browser doesn't support SSLv3, or only supports SSLv3 using stream ciphers". See pic. Did you think poodletest.com is inaccurate?   | |
|   |   | 
| Advert | |
|  | 
|  10-29-2014, 10:38 PM | #6 | 
| Ex-Helpdesk Junkie            Posts: 19,421 Karma: 85400180 Join Date: Nov 2012 Location: The Beaten Path, USA, Roundworld, This Side of Infinity Device: Kindle Touch fw5.3.7 (Wifi only) | 
			
			It is possible some other part of your PC setup protected you. But I am running the same FF release and am vulnerable, so I'd trust Mozilla on this.    | 
|   |   | 
|  10-29-2014, 10:39 PM | #7 | |
| Addict            Posts: 219 Karma: 1000210 Join Date: Mar 2014 Device: Kobo | Quote: 
 https://www.poodletest.com/ If your browser is not vulnerable, you will see a Springfield Terrier and "not vulnerable" as in my pic earlier. If your browser is vulnerable, you will see a poodle with the "vulnerable" caption. You will know for sure you are not vulnerable when you upgrade to Firefox 34 which will be released Nov 25. Internet Explorer is at present vulnerable, Microsoft is working on fixing this, I expect a patch will be delivered via Windows Update sometime in future. | |
|   |   | 
|  10-29-2014, 10:41 PM | #8 | 
| Addict            Posts: 219 Karma: 1000210 Join Date: Mar 2014 Device: Kobo | |
|   |   | 
|  10-29-2014, 10:45 PM | #9 | |
| Treachery of images ...            Posts: 4,149 Karma: 94320195 Join Date: May 2012 Location: Australia Device: Sony 650, Kobo Glo, H2O, Aura One, Forma, Libra 2, Libra Colour | Quote: 
 What I'm asking is how would someone know if they had been affected. What symptoms so to speak. | |
|   |   | 
|  10-29-2014, 10:46 PM | #10 | |
| Ex-Helpdesk Junkie            Posts: 19,421 Karma: 85400180 Join Date: Nov 2012 Location: The Beaten Path, USA, Roundworld, This Side of Infinity Device: Kindle Touch fw5.3.7 (Wifi only) | Quote: 
 In general these sort of tests are better for proving the presence of vulnerabilities, because if you are vulnerable once you can and will be again. However, saying you aren't vulnerable... is it because you truly are protected, or because anything down to a random glitch prevented the connection going through and thus fooled the test? I remember the same confusion wih the Heartbleed tests, but at least those warned you of the uncertainty. | |
|   |   | 
|  10-29-2014, 10:49 PM | #11 | 
| Ex-Helpdesk Junkie            Posts: 19,421 Karma: 85400180 Join Date: Nov 2012 Location: The Beaten Path, USA, Roundworld, This Side of Infinity Device: Kindle Touch fw5.3.7 (Wifi only) | |
|   |   | 
|  10-29-2014, 10:55 PM | #12 | 
| Surfin the alpha waves ~~            Posts: 26,714 Karma: 459765791 Join Date: Dec 2010 Location: New Jersey Device: Jetbook Lite & Mini, Nook STR, Kobo, Hanvon N516, Kindle 2, Androids | |
|   |   | 
|  10-29-2014, 11:03 PM | #13 | |
| Addict            Posts: 219 Karma: 1000210 Join Date: Mar 2014 Device: Kobo | Quote: 
 SSL Labs link to test Poodle vulnerability: https://www.ssllabs.com/ssltest/viewMyClient.html   | |
|   |   | 
|  10-29-2014, 11:04 PM | #14 | |
| Addict            Posts: 376 Karma: 6405689 Join Date: Nov 2012 Location: US Device: Kindle 4 NT, Paperwhite | 
			
			As far as I know, there isn't any widespread attack taking advantage of POODLE yet. I believe that full protection in Firefox will come when they change the default setting to disable SSLv3 in FF34 which will be released 11/25/2014. Or you can turn it off yourself now. If you want to disable SSLv3 in Internet Explorer (which is easy) or Firefox (pretty easy) or Chrome (involves modifying the shortcut you use to launch it), there are detailed instructions here (scroll down a bit). Note that if you are still using IE6, you also need to enable TLS 1.0 because it's not enabled by default. No one should still be using SSLv3 anymore (it was developed by Netscape in 1996 and later replaced by TLS) but it's possible some ancient website still is. Here's a comment from one of the SANS ISC articles Quote: 
 For more technical information: SSL 3 is dead, killed by the POODLE attack POODLE: Turning off SSLv3 for various servers and client SSLv3 POODLE Vulnerability Official Release Last edited by bookmarked; 10-29-2014 at 11:20 PM. Reason: fixed URL | |
|   |   | 
|  10-29-2014, 11:07 PM | #15 | |
| Addict            Posts: 219 Karma: 1000210 Join Date: Mar 2014 Device: Kobo | Quote: 
 At this point, I believe my FF 33.0.2 is vulnerable. There is also a SSL Lab test: https://www.ssllabs.com/ssltest/viewMyClient.html | |
|   |   | 
|  | 
| 
 | 
|  Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post | 
| Short Fiction Anstey, F: The black poodle, and other tales. V1. 23 Sep 2012 | crutledge | Kindle Books | 0 | 09-23-2012 11:30 AM | 
| Short Fiction Anstey, F: The black poodle, and other tales. V1. 23 Sep 2012 | crutledge | ePub Books | 0 | 09-23-2012 11:29 AM | 
| Short Fiction Anstey, F: The black poodle, and other tales. V1. 23 Sep 2012 | crutledge | BBeB/LRF Books | 0 | 09-23-2012 11:28 AM | 
| Free (Kindle UK) Alexandra's Legacy: Legacy, Book 1 by N. J. Walters | arcadata | Deals and Resources (No Self-Promotion or Affiliate Links) | 3 | 09-01-2011 12:33 PM | 
| my story has been frozen ever since i downgraded it | haianh0402 | iRiver Story | 11 | 08-09-2010 03:25 AM |