GNU/Linux ◆ screen ◆ zsh 12296 views

Poodle Proof of Concept (Padding Oracle On Downgraded Legacy Encryption)

Github Repo - Website

This PoC explore the cryptography behind the attack, it can be assimilate to the MiTM. Poodle allow you to retrieve plaintext messages if the Transport Layer Security used is SSLv3 (I also made a point for TLS1.0). It does not allow you to retrieve the private key used to encrypt the message or the request HTTP.