|
![]() |
|
Thread Tools | Search this Thread |
![]() |
#1 | ||
Treachery of images ...
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 4,121
Karma: 93720365
Join Date: May 2012
Location: Australia
Device: Sony 650, Kobo Glo, H2O, Aura One, Forma, Libra 2, Libra Colour
|
poodle - Padding Oracle On Downgraded Legacy Encryption SSL vulnerability
POODLE (Padding Oracle On Downgraded Legacy Encryption) SSL vulnerability - seems we have to be worried about poodles now.
![]() I confess to not really understanding much about this, but I'm sure that others on this forum will. Hereunder is some basic info and links. (And a big thank you to bookmarked in the Kobo Discounts thread who brought poodle to our attention ![]() Here's what Mozilla says: Quote:
From http://www.theregister.co.uk/2014/10..._fixit_for_ie/ Quote:
------------------ Apple said Wednesday it will stop supporting the encryption standard Secure Sockets Layer 3.0 for its push notifications service in response to a vulnerability identified earlier this month in the aging protocol. Spoiler:
A site that tests your browser for vulnerability issues: https://www.poodletest.com/ (And yep mine was vulnerable when I tested it, so I downloaded the Mozilla fix and now it's not) Last edited by Lynx-lynx; 10-29-2014 at 06:50 PM. Reason: add the word 'be' in the first sentence |
||
![]() |
![]() |
![]() |
#2 | |
Addict
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 219
Karma: 1000210
Join Date: Mar 2014
Device: Kobo
|
Quote:
My results: Firefox 33.0.2 is not vulnerable. Internet Explorer 11 is vulnerable. |
|
![]() |
![]() |
Advert | |
|
![]() |
#3 |
Ex-Helpdesk Junkie
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 19,421
Karma: 85400180
Join Date: Nov 2012
Location: The Beaten Path, USA, Roundworld, This Side of Infinity
Device: Kindle Touch fw5.3.7 (Wifi only)
|
FF 33.0.2 is vulnerable, Mozilla will disable SSLv3.0 in FF34.
|
![]() |
![]() |
![]() |
#4 |
Treachery of images ...
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 4,121
Karma: 93720365
Join Date: May 2012
Location: Australia
Device: Sony 650, Kobo Glo, H2O, Aura One, Forma, Libra 2, Libra Colour
|
How does one know if they've been affected by this vulnerability, I'm a bit confused ....
![]() |
![]() |
![]() |
![]() |
#5 | |
Addict
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 219
Karma: 1000210
Join Date: Mar 2014
Device: Kobo
|
Quote:
https://blog.mozilla.org/security/20...nd-of-ssl-3-0/ But when I run poodletest.com, the results are not vulnerable for Firefox 33.0.2. Poodletest.com reported "your browser doesn't support SSLv3, or only supports SSLv3 using stream ciphers". See pic. Did you think poodletest.com is inaccurate? ![]() |
|
![]() |
![]() |
Advert | |
|
![]() |
#6 |
Ex-Helpdesk Junkie
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 19,421
Karma: 85400180
Join Date: Nov 2012
Location: The Beaten Path, USA, Roundworld, This Side of Infinity
Device: Kindle Touch fw5.3.7 (Wifi only)
|
It is possible some other part of your PC setup protected you. But I am running the same FF release and am vulnerable, so I'd trust Mozilla on this.
![]() |
![]() |
![]() |
![]() |
#7 | |
Addict
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 219
Karma: 1000210
Join Date: Mar 2014
Device: Kobo
|
Quote:
https://www.poodletest.com/ If your browser is not vulnerable, you will see a Springfield Terrier and "not vulnerable" as in my pic earlier. If your browser is vulnerable, you will see a poodle with the "vulnerable" caption. You will know for sure you are not vulnerable when you upgrade to Firefox 34 which will be released Nov 25. Internet Explorer is at present vulnerable, Microsoft is working on fixing this, I expect a patch will be delivered via Windows Update sometime in future. |
|
![]() |
![]() |
![]() |
#8 |
Addict
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 219
Karma: 1000210
Join Date: Mar 2014
Device: Kobo
|
|
![]() |
![]() |
![]() |
#9 | |
Treachery of images ...
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 4,121
Karma: 93720365
Join Date: May 2012
Location: Australia
Device: Sony 650, Kobo Glo, H2O, Aura One, Forma, Libra 2, Libra Colour
|
Quote:
What I'm asking is how would someone know if they had been affected. What symptoms so to speak. |
|
![]() |
![]() |
![]() |
#10 | |
Ex-Helpdesk Junkie
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 19,421
Karma: 85400180
Join Date: Nov 2012
Location: The Beaten Path, USA, Roundworld, This Side of Infinity
Device: Kindle Touch fw5.3.7 (Wifi only)
|
Quote:
In general these sort of tests are better for proving the presence of vulnerabilities, because if you are vulnerable once you can and will be again. However, saying you aren't vulnerable... is it because you truly are protected, or because anything down to a random glitch prevented the connection going through and thus fooled the test? I remember the same confusion wih the Heartbleed tests, but at least those warned you of the uncertainty. |
|
![]() |
![]() |
![]() |
#11 |
Ex-Helpdesk Junkie
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 19,421
Karma: 85400180
Join Date: Nov 2012
Location: The Beaten Path, USA, Roundworld, This Side of Infinity
Device: Kindle Touch fw5.3.7 (Wifi only)
|
|
![]() |
![]() |
![]() |
#12 |
Surfin the alpha waves ~~
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 26,281
Karma: 459765791
Join Date: Dec 2010
Location: New Jersey
Device: Jetbook Lite & Mini, Nook STR, Kobo, Hanvon N516, Kindle 2, Androids
|
|
![]() |
![]() |
![]() |
#13 | |
Addict
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 219
Karma: 1000210
Join Date: Mar 2014
Device: Kobo
|
Quote:
SSL Labs link to test Poodle vulnerability: https://www.ssllabs.com/ssltest/viewMyClient.html ![]() |
|
![]() |
![]() |
![]() |
#14 | |
Addict
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 373
Karma: 6346855
Join Date: Nov 2012
Location: US
Device: Kindle 4 NT, Paperwhite
|
As far as I know, there isn't any widespread attack taking advantage of POODLE yet.
I believe that full protection in Firefox will come when they change the default setting to disable SSLv3 in FF34 which will be released 11/25/2014. Or you can turn it off yourself now. If you want to disable SSLv3 in Internet Explorer (which is easy) or Firefox (pretty easy) or Chrome (involves modifying the shortcut you use to launch it), there are detailed instructions here (scroll down a bit). Note that if you are still using IE6, you also need to enable TLS 1.0 because it's not enabled by default. No one should still be using SSLv3 anymore (it was developed by Netscape in 1996 and later replaced by TLS) but it's possible some ancient website still is. Here's a comment from one of the SANS ISC articles Quote:
For more technical information: SSL 3 is dead, killed by the POODLE attack POODLE: Turning off SSLv3 for various servers and client SSLv3 POODLE Vulnerability Official Release Last edited by bookmarked; 10-29-2014 at 11:20 PM. Reason: fixed URL |
|
![]() |
![]() |
![]() |
#15 | |
Addict
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 219
Karma: 1000210
Join Date: Mar 2014
Device: Kobo
|
Quote:
At this point, I believe my FF 33.0.2 is vulnerable. There is also a SSL Lab test: https://www.ssllabs.com/ssltest/viewMyClient.html |
|
![]() |
![]() |
![]() |
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Short Fiction Anstey, F: The black poodle, and other tales. V1. 23 Sep 2012 | crutledge | Kindle Books | 0 | 09-23-2012 11:30 AM |
Short Fiction Anstey, F: The black poodle, and other tales. V1. 23 Sep 2012 | crutledge | ePub Books | 0 | 09-23-2012 11:29 AM |
Short Fiction Anstey, F: The black poodle, and other tales. V1. 23 Sep 2012 | crutledge | BBeB/LRF Books | 0 | 09-23-2012 11:28 AM |
Free (Kindle UK) Alexandra's Legacy: Legacy, Book 1 by N. J. Walters | arcadata | Deals and Resources (No Self-Promotion or Affiliate Links) | 3 | 09-01-2011 12:33 PM |
my story has been frozen ever since i downgraded it | haianh0402 | iRiver Story | 11 | 08-09-2010 03:25 AM |