POODLE (Padding Oracle On Downgraded Legacy Encryption) is a design vulnerability in SSL 3.0 CBC-mode record processing. SSL 3.0 uses nondeterministic CBC padding, enabling a padding oracle that can reveal plaintext when an active attacker modifies ciphertext and observes the victim’s repeated SSL 3.0 requests. The issue affects SSL 3.0 implementations, including OpenSSL through 1.0.1i, rather than TLS 1.0, TLS 1.1, or TLS 1.2 themselves.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (4 hidden).
Repository is very small and purpose-built: a minimal README plus one Python exploit script, cve_2014_3566_poodle_exploit.py. The script is presented as an active exploit for CVE-2014-3566 (POODLE), not merely a detector. Its structure includes an SSLRecord dataclass for record representation, an SSLv3Parser class for constructing/parsing SSL 3.0 records and crafting a downgrade-oriented ClientHello, and a PaddingOracle class that sends manipulated SSLv3 application-data records and interprets alert behavior to distinguish valid vs invalid padding. The visible code shows explicit SSLv3 constants, handshake/alert parsing, ciphertext mutation, and byte-by-byte oracle logic. The main routine exposes CLI arguments for target host, target port, verbosity, and an optional local proxy port, then instantiates a POODLEExploiter object and either runs a standalone attack or starts a man-in-the-middle proxy. Based on the script description and visible control flow, the exploit’s intended capabilities are: downgrade a connection to SSL 3.0, intercept encrypted traffic, perform padding-oracle decryption against CBC records, and recover sensitive plaintext such as session cookies or authentication tokens. No hardcoded external URLs, domains, or IPs are embedded; endpoints are runtime-supplied target host/port values and a local proxy listener. Overall, this is an operational Python proof-of-concept/exploitation tool for network/web targets using vulnerable legacy SSL 3.0 behavior.
This repository is a Python-based POODLE (CVE-2014-3566) LDAPS attack demo with both CLI and web UI front ends. It is not a generic framework module; it is a standalone educational/operational proof-of-concept that combines real network verification with a working padding-oracle engine. Repository structure: cli.py provides a terminal workflow with three phases: SSLv3 verification, LDAP bind testing, and password recovery. server.py exposes the same workflow through Flask + Socket.IO, while templates/index.html and static/main.js/style.css implement the browser UI. poodle_engine.py contains the core attack logic and supports two modes: a local simulation oracle for offline demonstration and a RealOracle mode that performs live SSL 3.0 queries against a target. real_oracle.py builds crafted LDAP bind messages, computes alignment values for each target byte, and performs ciphertext block substitution to distinguish HIT/MISS conditions from server responses. ssl3_client.py is a custom raw-socket SSLv3 client implementing handshake, key derivation, MAC, CBC padding, and record encryption/decryption for AES-CBC and 3DES-CBC suites. ssl3_verify.py wraps external nmap and openssl commands to confirm SSLv3/POODLE exposure and to perform a real LDAP simple bind over SSLv3. Main exploit capabilities: (1) detect whether a target LDAPS service accepts SSL 3.0 and likely CBC ciphers; (2) authenticate to the target with an LDAP simple bind over SSLv3; (3) in real-oracle mode, repeatedly open fresh SSLv3 connections, encrypt crafted LDAP bind requests, replace the last ciphertext block with a target block, send the modified record, and infer plaintext bytes based on whether the server returns application data or a TLS alert; (4) in simulation mode, demonstrate the same byte-recovery math without network access. The attack is aimed at LDAPS services, especially lab Windows/SCHANNEL-style targets, with defaults set to 192.168.56.50:636 and bind DN labuser@lab.local. Notable observables: default target 192.168.56.50:636, local web server on 0.0.0.0:5000, default bind DN labuser@lab.local, default demo password LabUser@123, and LDAP control OID 1.1 used for alignment padding. The code also depends on external nmap scripts ssl-poodle and ssl-enum-ciphers plus openssl s_client for verification. Overall, this is a real exploit demo rather than a mere detector: it includes custom SSLv3 protocol handling and logic to recover plaintext byte-by-byte via a POODLE padding oracle against LDAPS.
This repository is a comprehensive POODLE (CVE-2014-3566) attack sandbox, designed to demonstrate and test the POODLE vulnerability in SSLv3. The structure includes Dockerfiles and configuration for three main containers: a client, a MITM (man-in-the-middle) server, and a target Nginx server. The Nginx server is configured to only support SSLv3 and the DES-CBC3-SHA cipher, making it intentionally vulnerable. The client scripts (JavaScript) generate SSLv3 requests to the target, while the MITM server (Python scripts using Scapy and NetfilterQueue) intercepts, inspects, and manipulates SSL/TLS packets to perform the POODLE attack. The MITM server also exposes HTTP endpoints (e.g., /blocksize, /offset, /nextRequest) to coordinate the attack with the client. The repository includes various test and utility scripts for packet manipulation, cryptographic operations, and traffic analysis. The exploit is operational and demonstrates the full attack chain, from network setup to decryption of secure data, in a controlled environment. No fake or detection-only scripts are present; the code is a real exploit implementation for educational and research purposes.
This repository provides a comprehensive proof-of-concept (PoC) implementation of the POODLE (Padding Oracle On Downgraded Legacy Encryption) attack (CVE-2014-3566), which targets SSLv3 with CBC cipher suites. The main exploit script is 'poodle-exploit.py', a Python3 tool that acts as a man-in-the-middle proxy to intercept and manipulate SSLv3 traffic between a client and a server. It allows the attacker to decrypt sensitive data (such as cookies) from encrypted sessions by exploiting the padding oracle vulnerability in SSLv3. The attack requires the ability to downgrade the victim's connection to SSLv3 and to inject JavaScript (e.g., via XSS) to trigger repeated requests. Supporting files include: - 'nginx-config': Example Nginx configuration to set up a test server with SSLv3 and a vulnerable cipher suite (DES-CBC3-SHA). - 'poodle.js': JavaScript code to automate sending crafted requests from the victim's browser, simulating the attacker's ability to influence request structure. - 'parallelization-poodle.py' and 'poodle-poc.py': Python scripts demonstrating the cryptographic principles and block-wise decryption logic behind the attack, useful for educational purposes. - 'request-splitter.py': Utility to analyze how sensitive data aligns with cipher blocks in HTTP requests. The repository is well-documented, with a detailed README explaining the attack, cryptographic background, and usage instructions. The exploit is a functional PoC, not weaponized, and is intended for research and educational use. It does not include a customizable payload but demonstrates the ability to recover plaintext from SSLv3-encrypted sessions under the right conditions.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A padding-oracle vulnerability affecting SSL 3.0 CBC encryption that can allow a man-in-the-middle attacker to recover encrypted data by exploiting SSL 3.0 padding behavior and protocol downgrade conditions.
The POODLE vulnerability, cited as an example of how CVSS may underrepresent real-world context despite broad impact across websites at disclosure time.
An information disclosure vulnerability in the SSL 3.0 protocol design caused by lack of CBC block cipher padding verification, enabling a man-in-the-middle attacker to decrypt portions of encrypted HTTPS traffic such as authentication cookies.
The SSLv3 POODLE vulnerability, referenced in test output showing the evaluated setup is not vulnerable because SSLv3 is disabled.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.