A Web hack that can endanger online
banking transactions is ranked the No. 1 new Web hacking technique
for 2010 in a top 10 list selected by a panel of experts and open voting.
Called the 1)Padding Oracle Crypto Attack, the hack takes advantage of how Microsoft's Web framework ASP.NET
protects AES encryption cookies.
If encryption data in the cookie has
been changed, the way ASP.NET handles it results in the application leaking
some information about how to decrypt the traffic. With enough repeated changes
and leaked information, the hacker can deduce which possible bytes can be
eliminated from the encryption key. That reduces the number of unknown bytes to
a small enough number to be guessed.