1 – 5 of 5
Anonymous Anonymous said...

Does this apply to SSLv2 as well?

October 14, 2014 at 7:39 PM

Blogger Scott Ruebush said...

I can't wait to see POODLE take over the internet! Thank goodness we have heroes to save us from the evils of SSL 3.0 and such and such, etc.

October 14, 2014 at 8:52 PM

Blogger Paul said...

Not sure how to enable TLS_FALLBACK_SCSV on apache or nginx.

To test I just disabled SSLv2 and SSLv3 on my personal https web site, so far so good all browsers (modern) traffic goes thru.

October 14, 2014 at 9:11 PM

Blogger Anand said...

nvd still says it is under review. Is there a patch coming?

October 14, 2014 at 10:46 PM

Blogger aFoP said...

It's strange, but google.com is also vulnerable to POODLE attack:
https://www.ssllabs.com/ssltest/analyze.html?d=google.com&s=74.125.239.96&hideResults=on

October 20, 2014 at 8:24 AM