The green icon in your browser should give you the green light to use confidential information safely: bank transactions, personal details, medical data and more. Yet it seems more than a traffic light is needed to tell you whether you are truly safe.
POODLE has now joined the list of recently discovered IT vulnerabilities, following ShellShock, Beast, Heartbleed and other revelations. Although Poodle sounds friendlier, the name stands for Padding Oracle On Downgraded Legacy Encryption, and it can have a serious impact on the security of your systems and communications. Poodle is a vulnerability in SSL version 3 encryption technology, after SSL version 2 had already proved insecure. SSL3 is used in OpenSSL, among other products, and is an outdated part of the SSL protocol still used mainly for communication with older, legacy applications.
Poodle needs access to the user's SSL communications to cause harm. This happens through a man-in-the-middle (MitM) attack, in which an attacker can inject certain JavaScript code into a user's session. The easiest and most common route is an open, unsecured Wi-Fi network, although other options exist. Once the attacker identifies the SSL communication, it can be intercepted and manipulated to gain access to the user's SSL-protected websites and communications. What the attacker then intends to do with this supposedly secure data is not hard to imagine.
Alongside Poodle, vulnerabilities have also been announced in the SHA1 algorithm, still widely used for SSL certificates and digital signatures. A worldwide transition to SHA2 algorithms is now underway to avoid these vulnerabilities. Systems still using SHA1 need to be changed now, even if their certificates remain valid into 2015 or beyond.
As SSL comes under worldwide scrutiny, other aspects that could lead to vulnerabilities are also being changed. For example, SSL certificates for internal server names, such as .local, are no longer issued and must be replaced.
How serious are Poodle and these SSL issues for you and your organisation? Less serious than Heartbleed and ShellShock mentioned earlier, but serious enough to act on immediately. The first step is relatively easy for any organisation or user: disable SSL2 and SSL3 on all systems, web applications, browsers and elsewhere, and move to TLS (1.0/1.2). Instructions are easy to find online.
Replace all your SHA1 certificates with SHA2 certificates as well. This can often be done free of charge; your certificate provider can advise you. Before making any changes, take the necessary system backups so that nothing can go wrong. Restart all modified systems and check that they work correctly.
Quick To-do List (Server Administrators)
- Replace your old certificates with a SHA2 certificate or better; this can often be done free of charge
- Install these certificates, root certificates and intermediate certificates
- Disable SSL2.0 and SSL3.0 on your system, for example for OWA on IIS, and enable TLS1.0 / TLS 1.2.
- Disable weak cipher suites and allow only strong cipher suites
- Restart the machines if necessary and check at https://www.ssllabs.com/ whether your SSL and certificate configuration is correct
See the following for background information and guidance
- Detailed information about SSL3 and Poodle
- Blog about SSL3, Poodle and proposed changes
- PowerScript for Microsoft IIS for TLS 1.1/1.2
- SSLv3 Poodle vulnerability explained for non-specialists (Security.nl)
But if you want to be truly sure this poodle or other SSL vulnerabilities are not making off with your data, SECWATCH Vulnerability Management offers the better solution. It shows you exactly where the vulnerabilities are and how we can resolve them for you.
