SSLv3 Poodle Vulnerability On WhatsApp.com & Blog.WhatsApp.com

What is the POODLE attack?

Padding Oracle On Downgraded Legacy Encryption (POODLE) is an issue that affects SSL 3.0. If an adversary can modify network transmissions between the client and the server they can downgrade the SSL connection to SSL 3.0 and tamper with/decrypt data in transmission.

The actual problem stems from the fact that the block cipher padding in CBC encryption in SSL 3.0 is not fully verified during the decryption process.

Is WhatsApp.com & Blog.WhatsApp.com vulnerable to POODLE?


root@pasuruanblackhat:/home/shan# openssl s_client -connect blog.whatsapp.com:443 -ssl3

Output :  

CONNECTED(00000003)
depth=2 C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert Global Root CA
verify return:1
depth=1 C = US, O = DigiCert Inc, CN = DigiCert SHA2 Secure Server CA
verify return:1
depth=0 C = US, ST = California, L = Santa Clara, O = "WhatsApp, Inc.", CN = *.whatsapp.com
verify return:1
---
Certificate chain
0 s:/C=US/ST=California/L=Santa Clara/O=WhatsApp, Inc./CN=*.whatsapp.com
i:/C=US/O=DigiCert Inc/CN=DigiCert SHA2 Secure Server CA
1 s:/C=US/O=DigiCert Inc/CN=DigiCert SHA2 Secure Server CA
i:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert Global Root CA
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIFJjCCBA6gAwIBAgIQBVDDa7GxLjszOo2izKc2FjANBgkqhkiG9w0BAQsFADBN
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMScwJQYDVQQDEx5E
aWdpQ2VydCBTSEEyIFNlY3VyZSBTZXJ2ZXIgQ0EwHhcNMTYwNjE2MDAwMDAwWhcN
MTkwOTA5MTIwMDAwWjBqMQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5p
YTEUMBIGA1UEBxMLU2FudGEgQ2xhcmExFzAVBgNVBAoTDldoYXRzQXBwLCBJbmMu
MRcwFQYDVQQDDA4qLndoYXRzYXBwLmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBANNq/Wj47PE6K20BfJL3mDf2/DoZkUoZqH+Fp2tGsuGjZvZjT+eQ
g88AAKd6aEg4BArnw9WW9CqVIbUE5MMjzVaBks00DzJnfmTZQVIILkMtKtPClXr2
IDYQ+jbyGC7l8WpAea44XRokjmShhaLE392Jm6kC6cykXEq8olqJxXRtFOV+cbiX
+dDRBvDMpMtm1aiM4SUnSz+A2xwUyuy4NYn25i424zuanAOUGOLpHWZNT3TSWBab
RM2dglOthRC/czq/HJ5FzKeKwD6rxzHO72CsGZ4Dvat9TAi20ooLOoTPUKhpoNcp
BGVfjmVPPaRcZI2BD+Nh4LBrny0plM50/XMCAwEAAaOCAeMwggHfMB8GA1UdIwQY
MBaAFA+AYRyCMWHVLyjnjUY4tCzhxtniMB0GA1UdDgQWBBQz+s7vmZYP3Vw6l6wq
2tZlKOp/mDAnBgNVHREEIDAegg4qLndoYXRzYXBwLmNvbYIMd2hhdHNhcHAuY29t
MA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIw
awYDVR0fBGQwYjAvoC2gK4YpaHR0cDovL2NybDMuZGlnaWNlcnQuY29tL3NzY2Et
c2hhMi1nNS5jcmwwL6AtoCuGKWh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9zc2Nh
LXNoYTItZzUuY3JsMEwGA1UdIARFMEMwNwYJYIZIAYb9bAEBMCowKAYIKwYBBQUH
AgEWHGh0dHBzOi8vd3d3LmRpZ2ljZXJ0LmNvbS9DUFMwCAYGZ4EMAQICMHwGCCsG
AQUFBwEBBHAwbjAkBggrBgEFBQcwAYYYaHR0cDovL29jc3AuZGlnaWNlcnQuY29t
MEYGCCsGAQUFBzAChjpodHRwOi8vY2FjZXJ0cy5kaWdpY2VydC5jb20vRGlnaUNl
cnRTSEEyU2VjdXJlU2VydmVyQ0EuY3J0MAwGA1UdEwEB/wQCMAAwDQYJKoZIhvcN
AQELBQADggEBAGLNjnV3CIW7xT0OhLQQdGVeMnlqTPnsXjVZlP6fKDB1T0uDoRpS
HpvZdN8G0U1HFeqcuFAn+U4iLhMwhqOKwHZc6kyMzIgF8t/HnnPgbwPWSDA1GL5m
lg+GN16aJK/NOFBmr2PYV6m0O3flVii+VL9H91pGuT6SMfgaLQOuGU92iKcs2EO0
gPOu3EautX+MGKxerD9hV4QSLhNt386SY5BE7ssu368XFI1woHZpUTzSR44jmNqZ
VkZKwxI56W1pMtoCtJz0nV3CURAsm5eD/VP3PdmqcrRWCL5fRx/gVfOPxTR3huyL
Ek0LpFD0WPyCpZe1NYF20SFhP4jPinwA2xA=
-----END CERTIFICATE-----
subject=/C=US/ST=California/L=Santa Clara/O=WhatsApp, Inc./CN=*.whatsapp.com
issuer=/C=US/O=DigiCert Inc/CN=DigiCert SHA2 Secure Server CA
---
No client certificate CA names sent
Server Temp Key: ECDH, P-256, 256 bits
---
SSL handshake has read 3022 bytes and written 306 bytes
---
New, TLSv1/SSLv3, Cipher is ECDHE-RSA-AES128-SHA
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
Protocol : SSLv3
Cipher : ECDHE-RSA-AES128-SHA
Session-ID: AAE9DA17B541DD565A1EB801BA0971F1F032681D8A7DE59735BC0557F17A9E07
Session-ID-ctx: 
Master-Key: A1835B491468B963556730890740F24755C8BA89B48896CBB3616B8C8DBD2E1E1226B89EF023587D8FB629EB8CF0772F
Key-Arg : None
PSK identity: None
PSK identity hint: None
SRP username: None
Start Time: 1491902165
Timeout : 7200 (sec)
Verify return code: 0 (ok)
---

How Much Bounty ? 

Sadly, this is not get the bounty.


Unlucky Me.

Reference :

Comments

Popular posts from this blog

Missing CSRF Token On Add Admin [Popoji CMS]

Session not expired When logout [partners.uber.com]

Open Redirect On Codepolitan.com