Two researchers have released a tool which can be used to crack web server-encrypted session data contained in cookies and parameters hidden in HTML pages. The method used by Juliano Rizzo and Thai Duong's Padding Oracle Exploitation Tool (Poet) can also be used to crack CAPTCHAS.. Poet utilises the Padding Oracle AttackPDF, first discovered in 2002, to decrypt cypher block chaining (CBC) mode encrypted data without the key. Web applications such as those generated using the popular JavaServer Faces framework (JSF) are affected. The Padding Oracle Attack makes use of the fact that during encryption individual blocks must always be 8 or 16 bytes long. In order to meet this requirement it is usually necessary to pad out the final block with additional bytes. There are various methods of performing this padding, some of which facilitate cracking. This is where Padding Oracle The link for this article located at H Security is no longer available. . Poet utilises the Padding Oracle AttackPDF, first discovered in 2002, to decrypt cypher block chaini. researchers, released, which, crack, server-encrypted, session. . LinuxSecurity.com Team
Two people have been successfully prosecuted for refusing to provide authorities with their encryption keys, resulting in landmark convictions that may have carried jail sentences of up to five years. The government said today it does not know their fate.. The power to force people to unscramble their data was granted to authorities in October 2007. Between 1 April, 2008 and 31 March this year the first two convictions were obtained. The disclosure was made by Sir Christopher Rose, the government's Chief Surveillance Commissioner, in his recent annual report. The former High Court judge did not provide details of the crimes being investigated in the case of either individual - neither of whom were necessarily suspects - nor of the sentences they received. The link for this article located at Out-Law is no longer available. . The power to force people to unscramble their data was granted to authorities in October 2007. Betwe. people, successfully, prosecuted, refusing, provide, authorities, their, encrypti. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.