SSL v3 POODLE vulnerability

Discuss how to use FL Studio

Return to “FL Studio Users Forum (Looptalk)”

Forum rules
Please read them here.
[You can only see part of this thread as you are not logged in to the forums]
EOD
Mon Oct 20, 2014 11:32 am

x

SSL v3 POODLE vulnerability

Everyone should disable V3/V2 in their browsers and IL, you should disable SSL V3 and V2 on your web server :)

How to fix your browser, Chrome/Firefox, etc : https://zmap.io/sslv3/browsers.html

As an additional tool you can visit https://www.ssllabs.com/ssltest/viewMyClient.html to check if your browser has been in fact changed (once you've disabled SSL V2 and V3)
POODLE.png
Here are some additional resources for assistance with remediation:
• Microsoft - https://technet.microsoft.com/library/s ... 09008.aspx
• Apache - http://httpd.apache.org/docs/2.2/ssl/ssl_faq.html#msie
• Tomcat - http://tomcat.apache.org/tomcat-6.0-doc/apr.html#HTTPS
• Nginx - http://nginx.com/blog/nginx-poodle-ssl/
• F5 Big IP - https://devcentral.f5.com/articles/cve- ... rom-big-ip
• Red Hat - https://access.redhat.com/articles/1232123

This vulnerability does not affect SSL certificates themselves. It impacts SSL protocol functionality. There is no need to reissue and revoke your current certificates. The Poodle vulnerability affects servers running SSL 3.0. It centers on cipher block chaining (CBC) encryption implementations that can allow attackers with a Man-in-the-Middle (MITM) position to view the content of an encrypted transmission.
You do not have the required permissions to view the files attached to this post.
Last edited by EOD on Mon Oct 20, 2014 6:17 pm, edited 1 time in total.




Return to “FL Studio Users Forum (Looptalk)”