Raccoon Attack
raccoon-attack.com
raccoon-attack.com
As this is a timing based attack, I wonder what the feasibility would be in a real-world network environment. From a brief skim of the paper, it looks like they were getting a false positive rate of 10% between two VMs on a Gigabit connection. I wonder how quickly that would increase if the servers were in different buildings / cities / continents.
and likely nothing else running.
Real world webservers running tons of concurrent requests have a very variable processing times (if you get below 5ms you are very good!) purely due to queued up work and context switches.
https://portswigger.net/daily-swig/researchers-exploit-http-...
>Raccoon is not an acronym. Raccoons are just cute animals, and it is well past time that an attack will be named after them :)
Better naming and mascot than the last five TLS security bugs if you ask me
Raccoon Obstical Course
I think DROWN was kiiinda pushing it.
Just to stoke some fires, I think poodle is also in that bag.
https://www.youtube.com/watch?v=LH8U4Nt4G40 (@ 6:33)
https://en.wikipedia.org/wiki/Pom_Poko
>Prominent scrotums are an integral part of tanuki folklore, and they are shown and referred to throughout the film, and also used frequently in their shape-shifting. This remains unchanged in the DVD release, though the English dub (but not the subtitles) refers to them as "raccoon pouches". Also, in the English dub and subtitles, the animals are never referred to as "raccoon dogs", which is the more accurate English name for the tanuki, instead they are incorrectly referred to as just "raccoons".
https://www.tofugu.com/japan/tanuki/
https://www.youtube.com/watch?v=icyOAc_pAvY
https://www.mariowiki.com/Tanooki_Suit
>The Tanooki Suit, or Tanooki Costume, is a fairly uncommon item found in Super Mario Bros. 3 and its subsequent remakes in Super Mario All-Stars and Super Mario Advance 4: Super Mario Bros. 3. It is based on tanukis, Japanese creatures who, according to mythology, can use leaves to shape-shift and cause chaos. The suit is an add-on to the Raccoon form that allows Mario or Luigi to temporarily turn into a statue and become immune to enemies and obstacles, in addition to flying and attacking enemies with tail swipes.
>According to Shigeru Miyamoto in the Super Mario Bros. 3 entry of the 25th Anniversary Super Mario History Booklet, he was aware that most players outside Japan would be overall confused with the Tanooki Suit and the transformation, but he left it in because he was too excited to remove it.
Is the top comment and most of the responses going to be about the "raccoon" in the name of the attack, or the first paragraph of the page (it's not really exploitable), and not on the actual content again? Only time will tell.
> Probably not. Raccoon is a complex timing attack and it is very hard to exploit.
Nice of them to put this up as one of the first non-technical bulletins.
No need to feed hysteria.
Good for them.
It's interesting that they emphasize this is a really hard problem to solve, and for 99% of use cases this really isn't an issue to worry about.
But if you work in national security or are sensitive to security threats from nation states, this would certainly be an absolutely critical item to address or understand.
National Security and nation states would absolutely use this as a target where billions of dollars or thousands of lives could be at stake.
Sometimes vulnerabilities are just valuable to science. The work that follows up from this could be valuable to CNE and SIGINT!
Did anyone ever show a working timing attack for a web service? Even assuming no DoS/request limiting is in place.
what would possess someone to introduce a padding oracle/side-channel into something that didnt even need it??
Almost everybody assigned the task of implementing this stuff (SSLv3, last century) didn't understand it, even for the old finite field DH where it's just about within the grasp of someone with high school mathematics if you insisted on having it explained before you implement. So it's just magic, and once one person does it wrong everybody else must do it wrong or lose interoperability.
And the "wrong" DH implementation works fine, except that it introduces a slightly larger side channel.
You mention a padding oracle, this isn't a padding oracle. It's an oracle because it provides the attacker with answers to questions they can't answer themselves, but there isn't any padding involved here.
And it's a pretty weak oracle, the insight you gain from asking the oracle questions is about a single pre-master secret, not the underlying DH private key or any long term authentication key.
Is there a reason for that? Not really following the scene, the same group of people finding these issues over the years and hence marketing is similar?