Open cardosec

Case DD4FBB · Cryptography · L4 Advanced

Padding Oracle Attacks

Practise as: Explain it · Deep dive
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. CBC decryption with PKCS#7 padding: an error that distinguishes bad padding from bad data is an oracle.
  2. Attacker flips bytes of the previous ciphertext block, ~256 guesses per byte, to recover plaintext without the key.
  3. Oracles leak via distinct errors, HTTP status codes, or timing (Lucky Thirteen against TLS CBC suites).
  4. Real cases: ASP.NET MS10-070, POODLE on SSLv3, Bleichenbacher/ROBOT on RSA PKCS#1 v1.5 encryption.
  5. Fix: use AEAD (AES-GCM), verify a MAC before decrypting, and return uniform, constant-time errors.

If the interviewer pushes back

  • How can a padding oracle be turned into an encryption oracle to forge arbitrary valid ciphertexts?
  • Why does Bleichenbacher work against RSA, and why did TLS 1.3 remove RSA key transport entirely?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.