[Cryptography] demonstrating SSLv2 weaknesses

Florian Weimer fw at deneb.enyo.de
Sun Jul 2 05:42:19 EDT 2017


* Robin Wood:

> So, are there any practical, walk through, demos attacking SSLv2, v3 or any
> of the other of the crypto that regularly gets written up as weak?

The SSLv2 truncation vulnerability should be practical to demonstrate,
except it may be tricky to find a HTTPS client which does not
reimplement it on top of later TLS versions.


More information about the cryptography mailing list