oss-sec mailing list archives

RE: Truly scary SSL 3.0 vuln to be revealed soon:


From: Sona Sarmadi <sona.sarmadi () enea com>
Date: Wed, 15 Oct 2014 05:28:34 +0000

Thanks Hanno,

A reflection: Maybe we shouldn't post  information like this here or somewhere else which is not published yet even if 
the information has leak out? Although all members here are reliable but it is still an open mailing list and we should 
be careful and act more responsible. 

Cheers
Sona

It's out:

https://www.openssl.org/~bodo/ssl-poodle.pdf
http://googleonlinesecurity.blogspot.de/2014/10/this-poodle-bites-
exploiting-ssl-30.html

My conclusion stays the same: Disable SSLv3.

--
Hanno Böck
http://hboeck.de/

mail/jabber: hanno () hboeck de
GPG: BBB51E42


Current thread: