DROWN
lorecryptographysecurity
A 2016 attack that breaks TLS by exploiting a server's support for obsolete SSLv2.
Decrypting RSA with Obsolete and Weakened eNcryption used a still-enabled SSLv2 endpoint sharing the same RSA key as a cross-protocol oracle to decrypt modern TLS sessions. The lesson was to fully disable SSLv2 everywhere a key is used.
Also known as: DROWN, Decrypting RSA with Obsolete and Weakened eNcryption, CVE-2016-0800
Sources
- CVE-2016-0800 (2016)