此SSL3.0的弱點可以通過中間人攻擊解密“安全”的HTTP cookies,使用技術先發動BEAST攻擊然後再發動的獅子狗(POODLE)攻擊,那要如何解決這樣的問題呢?
第二種就是讓瀏覽器支援TLS_FALLBACK_SCSV 機制,這機制就是在交握的時候,拒絕降級通訊協定的攻擊界接(TLS1.2,TLS嘗試下一個1.1,那麼TLS1.0,然後SSL3.0),使用TLS_FALLBACK_SCSV將確保SSL 3.0攻擊者可以不再強制降級的協議.
也鑒於如此的漏洞,又加上GOOGLE的工程師發現POODLE的攻擊,GOOGLE CHROME瀏覽器,已經宣布未來幾個月內將完全不支援SSLV3.0,您可能認為這件事情跟我們沒太大關係,可是對於系統開發商以及一般需要與瀏覽器界接的開發者,這可是很重要的改變,所以不得採取對策因應此事!
以下是chrome 將停用SSLV3.0的說明,可參考看看!
Posted: Tuesday, October 14, 2014
This POODLE bites: exploiting the SSL 3.0 fallback
Today we are publishing details of a vulnerability in the design of SSL version 3.0. This vulnerability allows the plaintext of secure connections to be calculated by a network attacker. I discovered this issue in collaboration with Thai Duong and Krzysztof Kotowicz (also Googlers).
SSL 3.0 is nearly 18 years old, but support for it remains widespread. Most importantly, nearly all browsers support it and, in order to work around bugs in HTTPS servers, browsers will retry failed connections with older protocol versions, including SSL 3.0. Because a network attacker can cause connection failures, they can trigger the use of SSL 3.0 and then exploit this issue.
Disabling SSL 3.0 support, or CBC-mode ciphers with SSL 3.0, is sufficient to mitigate this issue, but presents significant compatibility problems, even today. Therefore our recommended response is to support TLS_FALLBACK_SCSV. This is a mechanism that solves the problems caused by retrying failed connections and thus prevents attackers from inducing browsers to use SSL 3.0. It also prevents downgrades from TLS 1.2 to 1.1 or 1.0 and so may help prevent future attacks.
Google Chrome and our servers have supported TLS_FALLBACK_SCSV since February and thus we have good evidence that it can be used without compatibility problems. Additionally, Google Chrome will begin testing changes today that disable the fallback to SSL 3.0. This change will break some sites and those sites will need to be updated quickly.
In the coming months, we hope to remove support for SSL 3.0 completely from our client products.
Thank you to all the people who helped review and discuss responses to this issue.
Posted by Bodo Möller, Google Security Team