Fwd: [ PRIVACY Forum ] 'Padding Oracle' Crypto Attack Affects Millions of ASP.NET Apps

Steven Bellovin smb at cs.columbia.edu
Mon Sep 13 14:45:54 EDT 2010


Here's what happens when you get your integrity checks wrong....

Begin forwarded message:

> From: privacy at vortex.com
> Date: September 13, 2010 1:26:10 PM EDT
> To: privacy-list at vortex.com
> Subject: [ PRIVACY Forum ] 'Padding Oracle' Crypto Attack Affects Millions of ASP.NET Apps
> Reply-To: PRIVACY Forum Digest mailing list <privacy at vortex.com>
> 
> 
> 
> 'Padding Oracle' Crypto Attack Affects Millions of ASP.NET Apps
> 
> http://bit.ly/cnpzux  (threatpost)
> 
> --Lauren--
> Lauren Weinstein (lauren at vortex.com)
> http://www.vortex.com/lauren
> Tel: +1 (818) 225-2800
> Co-Founder, PFIR (People For Internet Responsibility): http://www.pfir.org
> Co-Founder, NNSquad (Network Neutrality Squad): http://www.nnsquad.org
> Founder, GCTIP (Global Coalition for Transparent Internet Performance): 
>   http://www.gctip.org
> Founder, PRIVACY Forum: http://www.vortex.com
> Member, ACM Committee on Computers and Public Policy
> Lauren's Blog: http://lauren.vortex.com
> Twitter: https://twitter.com/laurenweinstein
> Google Buzz: http://bit.ly/lauren-buzz
> 
> 
> 
> _______________________________________________
> privacy mailing list
> http://lists.vortex.com/mailman/listinfo/privacy
> 


		--Steve Bellovin, http://www.cs.columbia.edu/~smb





---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at metzdowd.com



More information about the cryptography mailing list