Case DD4FBB · Cryptography · L4 Advanced
Padding Oracle Attacks
Practise as: Explain it · Deep dive
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- CBC decryption with PKCS#7 padding: an error that distinguishes bad padding from bad data is an oracle.
- Attacker flips bytes of the previous ciphertext block, ~256 guesses per byte, to recover plaintext without the key.
- Oracles leak via distinct errors, HTTP status codes, or timing (Lucky Thirteen against TLS CBC suites).
- Real cases: ASP.NET MS10-070, POODLE on SSLv3, Bleichenbacher/ROBOT on RSA PKCS#1 v1.5 encryption.
- Fix: use AEAD (AES-GCM), verify a MAC before decrypting, and return uniform, constant-time errors.
If the interviewer pushes back
- How can a padding oracle be turned into an encryption oracle to forge arbitrary valid ciphertexts?
- Why does Bleichenbacher work against RSA, and why did TLS 1.3 remove RSA key transport entirely?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.