{"id":6492,"date":"2014-11-30T07:29:11","date_gmt":"2014-11-30T07:29:11","guid":{"rendered":"https:\/\/dev.railscarma.com\/poodle-ssl-security-threat-explored\/"},"modified":"2022-08-30T07:32:51","modified_gmt":"2022-08-30T07:32:51","slug":"menace-de-securite-ssl-caniche-exploree-2","status":"publish","type":"post","link":"https:\/\/www.railscarma.com\/fr\/blog\/articles-techniques\/menace-de-securite-ssl-caniche-exploree-2\/","title":{"rendered":"Poodle \u2013 Menace de s\u00e9curit\u00e9 SSL explor\u00e9e"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"6492\" class=\"elementor elementor-6492\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-3800d95d elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"3800d95d\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-69f90962\" data-id=\"69f90962\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-343fe574 elementor-widget elementor-widget-text-editor\" data-id=\"343fe574\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p style=\"text-align: justify;\"><strong>Caniche<\/strong>&nbsp;est une race de chien dont les pattes ressemblent \u00e0 des barbes \u00e0 papa. Il est intelligent et constitue un incontournable des expositions canines. M\u00eame les chiens les plus amicaux ont tendance \u00e0 mordre. Maintenant, nous voyons toutes sortes d&#039;alertes de s\u00e9curit\u00e9 et de snafus comme les saignements de c\u0153ur et les chocs d&#039;obus !!! Le dernier en date est POODLE.<\/p>\n<p style=\"text-align: justify;\">\n<\/p><p style=\"text-align: justify;\">Tout a commenc\u00e9 lorsqu&#039;une \u00e9quipe de Google a d\u00e9velopp\u00e9 et test\u00e9 une attaque nomm\u00e9e <strong>CANICHE<\/strong>&nbsp;(Padding Oracle On Downgraded Legacy Encryption) qui a d\u00e9couvert une vuln\u00e9rabilit\u00e9 dans le protocole Secure Sockets Layer (SSL) version 3 ou en abr\u00e9g\u00e9 SSLv3.<\/p>\n<p style=\"text-align: justify;\">SSLv3 est un cryptage obsol\u00e8te mais toujours utilis\u00e9 dans les navigateurs Web plus anciens et plus r\u00e9cents. (SSLv3 est un protocole vieux de 18 ans qui a \u00e9t\u00e9 remplac\u00e9 par le protocole TLS)<\/p>\n<p style=\"text-align: justify;\">POODLE essaie de forcer la connexion entre votre navigateur Web et le serveur \u00e0 passer \u00e0 SSLv3. L&#039;attaque POODLE profite de la fonctionnalit\u00e9 de n\u00e9gociation de version de protocole int\u00e9gr\u00e9e \u00e0 SSL\/TLS pour forcer l&#039;utilisation de SSL 3.0, puis utilise cette nouvelle vuln\u00e9rabilit\u00e9 pour d\u00e9crypter certains contenus au sein de la session SSL. Le d\u00e9cryptage se fait octet par octet et g\u00e9n\u00e9rera un grand nombre de connexions entre le client et le serveur.<\/p>\n<p style=\"text-align: justify;\"><strong>Comment font-ils?<\/strong><\/p>\n<p style=\"text-align: justify;\">Un attaquant peut ex\u00e9cuter un agent JavaScript sur un site Web pour que le navigateur de la victime envoie un cookie avec des requ\u00eates HTTPS \u00e0&nbsp;<b>https:\/\/xyz.com<\/b>, interceptez et modifiez les enregistrements SSL envoy\u00e9s par le navigateur de telle sorte qu&#039;il y ait une chance non n\u00e9gligeable que xyz.com accepte l&#039;enregistrement modifi\u00e9. Si l&#039;enregistrement modifi\u00e9 est accept\u00e9, l&#039;attaquant peut d\u00e9crypter un octet des cookies. Biscuits<\/p>\n<p style=\"text-align: justify;\">TLS 1.0 et les versions plus r\u00e9centes effectuent une validation plus robuste des donn\u00e9es d\u00e9chiffr\u00e9es et ne sont donc pas sensibles au m\u00eame probl\u00e8me. Mais pour SSLv3, il n&#039;y a pas de solution.<\/p>\n<p style=\"text-align: justify;\"><strong>\u00c0 quel point est-ce grave et comment cela vous affecte-t-il\u00a0?<\/strong><\/p>\n<p style=\"text-align: justify;\">Les connexions s\u00e9curis\u00e9es utilisent principalement TLS (le successeur de SSL), la plupart des utilisateurs deviennent vuln\u00e9rables car les navigateurs Web et les serveurs r\u00e9trograderont vers SSLv3 en cas de probl\u00e8mes pour n\u00e9gocier une session TLS. La plupart des impl\u00e9mentations SSL\/TLS restent r\u00e9trocompatibles avec SSL 3.0 pour interop\u00e9rer avec les syst\u00e8mes existants dans l&#039;int\u00e9r\u00eat d&#039;une exp\u00e9rience utilisateur fluide. Un attaquant effectuant une attaque de l&#039;homme du milieu pourrait d\u00e9clencher une r\u00e9trogradation du protocole vers SSLv3 et exploiter cette vuln\u00e9rabilit\u00e9 pour d\u00e9chiffrer un sous-ensemble de la communication crypt\u00e9e et en extraire des informations. La vuln\u00e9rabilit\u00e9 POODLE ne fonctionne que si le navigateur du client et la connexion du serveur prennent tous deux en charge SSLv3.<\/p>\n<p style=\"text-align: justify;\"><strong>Comment tester si mon navigateur est vuln\u00e9rable ?<\/strong><\/p>\n<p style=\"text-align: justify;\">Allez sur le site Web poodletest.com pour tester cela. Si vous voyez un caniche, vous \u00eates vuln\u00e9rable. Si vous voyez un Springfield Terrier, vous \u00eates en s\u00e9curit\u00e9.<\/p>\n<p style=\"text-align: justify;\">http:\/\/www.bolet.org\/TestSSLServer\/<br>http:\/\/code.google.com\/p\/sslaudit\/<\/p>\n<p style=\"text-align: justify;\"><strong>Que puis-je faire pour \u00e9viter cela ? Vaccin caniche ?<\/strong><\/p>\n<p style=\"text-align: justify;\">En tant qu&#039;utilisateur final, d\u00e9sactivez la prise en charge SSLv3 dans votre navigateur Web. S&#039;il est d\u00e9sactiv\u00e9, POODLE ne peut PAS r\u00e9trograder votre navigateur vers celui-ci. Pour encourager les meilleures pratiques de s\u00e9curit\u00e9, je recommande fortement d&#039;utiliser la version la plus \u00e9lev\u00e9e de TLS. Pour la plupart des navigateurs, cela devrait \u00eatre TLS 1.2.<strong><strong><br><\/strong><\/strong><\/p>\n<p style=\"text-align: justify;\"><strong>Cela affectera-t-il mon exp\u00e9rience de navigation\u00a0?<strong><br><\/strong><\/strong><\/p>\n<p style=\"text-align: justify;\">Cela aura un impact sur certains navigateurs plus anciens. Les sites Web qui ont d\u00e9j\u00e0 mis fin \u00e0 la prise en charge de SSLv3 deviendront incompatibles avec les anciens navigateurs et syst\u00e8mes d&#039;exploitation. Les anciens navigateurs comme Internet Explorer 6 fonctionnant sous Windows XP ou les versions ant\u00e9rieures verront une erreur de connexion SSL.<\/p>\n<p style=\"text-align: justify;\"><strong>SSLv3<\/strong>&nbsp;sera d\u00e9sactiv\u00e9 par d\u00e9faut dans les futures versions de nombreux navigateurs Web.<\/p>\n<p style=\"text-align: justify;\"><strong>Comment d\u00e9sactiver cela sur le serveur ?<\/strong><\/p>\n<p style=\"text-align: justify;\">CloudFlare a annonc\u00e9 qu&#039;il d\u00e9sactivait SSLv3 par d\u00e9faut sur ses serveurs. De nombreux prestataires de services l\u2019ont \u00e9galement fait.<\/p>\n<p style=\"text-align: justify;\">Si vous utilisez Apache, effectuez simplement cette modification dans votre configuration parmi les autres directives SSL\u00a0:<\/p>\n<p style=\"text-align: justify;\">Protocole SSL Tous -SSLv2 -SSLv3<\/p>\n<p style=\"text-align: justify;\">Cela d\u00e9sactive les versions 2 et 3 du protocole SSL.<\/p>\n<p style=\"text-align: justify;\"><strong>Comment les d\u00e9veloppeurs peuvent-ils emp\u00eacher cela\u00a0?<\/strong><strong><strong><br><\/strong><\/strong><\/p>\n<p style=\"text-align: justify;\"><b>.FILET<\/b><\/p>\n<p style=\"text-align: justify;\">Utilisez la propri\u00e9t\u00e9 SecurityProtocol pour activer TLS.<\/p>\n<p style=\"text-align: justify;\">Pour plus de d\u00e9tails sur l\u2019utilisation de la propri\u00e9t\u00e9 SecurityProtocol, visitez\u00a0:<\/p>\n<p style=\"text-align: justify;\">http:\/\/msdn.microsoft.com\/en-us\/library\/system.net.servicepointmanager.securityprotocol(v=vs.110).as&#8230;<\/p>\n<p style=\"text-align: justify;\">http:\/\/msdn.microsoft.com\/en-us\/library\/system.net.securityprotocoltype(v=vs.110).aspx<\/p>\n<p style=\"text-align: justify;\">\u00c0 titre d&#039;exemple, pour forcer TLS 1.2 dans une impl\u00e9mentation C# .NET, vous utiliseriez\u00a0:<\/p>\n<p style=\"text-align: justify;\">System.Net.ServicePointManager.SecurityProtocol = System.Net.SecurityProtocolType.Tls12;<\/p>\n<p style=\"text-align: justify;\"><b>JAVA<\/b><\/p>\n<p style=\"text-align: justify;\">REMARQUE\u00a0: TLS 1.2 a \u00e9t\u00e9 pris en charge pour la premi\u00e8re fois dans JDK 7 et sera celui par d\u00e9faut dans JDK 8\u00a0: https:\/\/blogs.oracle.com\/java-platform-group\/entry\/java_8_will_use_tls<\/p>\n<p style=\"text-align: justify;\"><strong>Utilisez la m\u00e9thode SSLContext.getInstance pour activer TLS.<\/strong><\/p>\n<p style=\"text-align: justify;\"><strong>Pour plus de d\u00e9tails sur l&#039;utilisation de la m\u00e9thode SSLContext.getInstance, visitez\u00a0:<\/strong><\/p>\n<p style=\"text-align: justify;\">http:\/\/docs.oracle.com\/javase\/7\/docs\/api\/javax\/net\/ssl\/SSLContext.html#getInstance(java.lang.String)<\/p>\n<p style=\"text-align: justify;\">http:\/\/docs.oracle.com\/javase\/7\/docs\/api\/javax\/net\/ssl\/SSLContext.html#getInstance(java.lang.String,&#8230;<\/p>\n<p style=\"text-align: justify;\">http:\/\/docs.oracle.com\/javase\/7\/docs\/technotes\/guides\/security\/StandardNames.html#SSLContext<\/p>\n<p style=\"text-align: justify;\">Par exemple, pour utiliser le fournisseur de couche de s\u00e9curit\u00e9 par d\u00e9faut pour activer TLS, vous utiliserez\u00a0:<\/p>\n<p style=\"text-align: justify;\">objet = SSLContext.getInstance(&quot;TLS&quot;);<\/p>\n<p style=\"text-align: justify;\"><strong>Pour forcer TLS 1.2 tout en utilisant l&#039;extension Java Secure Socket Extension (JSSE) de Sun, vous devez utiliser\u00a0:<\/strong><\/p>\n<p style=\"text-align: justify;\">objet = SSLConnect.getInstance(&quot;TLSv1.2&quot;, &quot;SunJSEE&quot;);<\/p>\n<p style=\"text-align: justify;\"><b>boucle<\/b><strong><strong><br><\/strong><\/strong><\/p>\n<p style=\"text-align: justify;\">Utilisez l&#039;option CURLOPT_SSLVERSION pour activer TLS.<\/p>\n<p style=\"text-align: justify;\">Pour plus de d\u00e9tails sur l&#039;utilisation de l&#039;option CURLOPT_SSLVERSION, visitez\u00a0:<\/p>\n<p style=\"text-align: justify;\">http:\/\/curl.haxx.se\/libcurl\/c\/CURLOPT_SSLVERSION.html<\/p>\n<p style=\"text-align: justify;\">\u00c0 titre d&#039;exemple, pour forcer cURL \u00e0 utiliser TLS 1.0 ou version ult\u00e9rieure, vous utiliseriez\u00a0:<\/p>\n<p style=\"text-align: justify;\">C\/C++\/C#\u00a0:<\/p>\n<p style=\"text-align: justify;\">curl_easy_setopt(curl, CURLOPT_SSLVERSION, CURL_SSLVERSION_TLSv1);<\/p>\n<p style=\"text-align: justify;\">PHP\u00a0:<\/p>\n<p style=\"text-align: justify;\">curl_setopt($curl_request, CURLOPT_SSLVERSION, CURL_SSLVERSION_TLSv1);<\/p>\n<p style=\"text-align: justify;\">Dans cURL 7.34.0 ou version ult\u00e9rieure, pour forcer TLS 1.2, vous utiliseriez\u00a0:<\/p>\n<p style=\"text-align: justify;\">C\/C++\/C#\u00a0:<\/p>\n<p style=\"text-align: justify;\">curl_easy_setopt(curl, CURLOPT_SSLVERSION, CURL_SSLVERSION_TLSv1_2);<\/p>\n<p style=\"text-align: justify;\">PHP\u00a0:<\/p>\n<p style=\"text-align: justify;\">curl_setopt($curl_request, CURLOPT_SSLVERSION, CURL_SSLVERSION_TLSv1_2);<\/p>\n<p style=\"text-align: justify;\"><a href=\"https:\/\/www.railscarma.com\/fr\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>RailsCarma<\/strong><\/a> L&#039;\u00e9quipe s&#039;est pr\u00e9par\u00e9e en mode d\u00e9fense compl\u00e8te pour boucher tous les trous laiss\u00e9s ouverts par cette vuln\u00e9rabilit\u00e9. Nous avons appliqu\u00e9 les correctifs n\u00e9cessaires \u00e0 nos applications pour d\u00e9sactiver les options SSL\/TLS non s\u00e9curis\u00e9es.<\/p>\n<h3 style=\"text-align: justify;\"><strong>Les r\u00e9f\u00e9rences<\/strong><\/h3>\n<p style=\"text-align: justify;\"><a href=\"http:\/\/community.developer.authorize.net\/t5\/The-Authorize-Net-Developer-Blog\/Important-POODLE-Information-Updated\/ba-p\/48163\">http:\/\/community.developer.authorize.net\/t5\/The-Authorize-Net-Developer-Blog\/Important-POODLE-Information-Updated\/ba-p\/48163<\/a><\/p>\n<p style=\"text-align: justify;\"><a href=\"http:\/\/arstechnica.com\/security\/2014\/10\/ssl-broken-again-in-poodle-attack\/\">http:\/\/arstechnica.com\/security\/2014\/10\/ssl-broken-again-in-poodle-attack\/<\/a><\/p>\n<p style=\"text-align: justify;\"><a href=\"https:\/\/zmap.io\/sslv3\/\">https:\/\/zmap.io\/sslv3\/<\/a><\/p>\n<p style=\"text-align: justify;\"><a href=\"https:\/\/www.imperialviolet.org\/2014\/10\/14\/poodle.html\">https:\/\/www.imperialviolet.org\/2014\/10\/14\/poodle.html<\/a><\/p>\n<p style=\"text-align: justify;\"><a href=\"http:\/\/blog.cryptographyengineering.com\/2014\/10\/attack-of-week-poodle.html\">http:\/\/blog.cryptographyengineering.com\/2014\/10\/attack-of-week-poodle.html<\/a><\/p>\n<p style=\"text-align: justify;\"><a href=\"https:\/\/blog.mozilla.org\/security\/2014\/10\/14\/the-poodle-attack-and-the-end-of-ssl-3-0\/\">https:\/\/blog.mozilla.org\/security\/2014\/10\/14\/the-poodle-attack-and-the-end-of-ssl-3-0\/<\/a><\/p>\n<p style=\"text-align: justify;\"><a href=\"http:\/\/www.theregister.co.uk\/2014\/10\/16\/poodle_analysis\/\">http:\/\/www.theregister.co.uk\/2014\/10\/16\/poodle_analysis\/<\/a><\/p>\n<p style=\"text-align: justify;\"><a href=\"http:\/\/www.theregister.co.uk\/2014\/10\/14\/google_drops_ssl_30_poodle_vulnerability\/\">http:\/\/www.theregister.co.uk\/2014\/10\/14\/google_drops_ssl_30_poodle_vulnerability\/<\/a><\/p>\n<p style=\"text-align: justify;\"><a href=\"http:\/\/www.pcworld.com\/article\/2834015\/security-experts-warn-of-poodle-attack-against-ssl-30.html\">http:\/\/www.pcworld.com\/article\/2834015\/security-experts-warn-of-poodle-attack-against-ssl-30.html<\/a><\/p>\n<p style=\"text-align: justify;\">http:\/\/www.alertlogic.com\/blog\/poodle-man-middle-attack-sslv3\/<\/p>\n<p style=\"text-align: justify;\"><a href=\"https:\/\/www.us-cert.gov\/ncas\/alerts\/TA14-290A\">https:\/\/www.us-cert.gov\/ncas\/alerts\/TA14-290A<\/a><\/p>\n<p style=\"text-align: justify;\"><a href=\"https:\/\/www.openssl.org\/~bodo\/ssl-poodle.pdf\">https:\/\/www.openssl.org\/~bodo\/ssl-poodle.pdf<\/a><\/p>\n<p style=\"text-align: justify;\"><a href=\"http:\/\/www.makeuseof.com\/tag\/stop-poodle-from-biting-your-browser\/\">http:\/\/www.makeuseof.com\/tag\/stop-poodle-from-biting-your-browser\/<\/a><\/p>\n<p style=\"text-align: justify;\"><a href=\"https:\/\/community.qualys.com\/blogs\/securitylabs\/2014\/10\/15\/ssl-3-is-dead-killed-by-the-poodle-attack\">https:\/\/community.qualys.com\/blogs\/securitylabs\/2014\/10\/15\/ssl-3-is-dead-killed-by-the-poodle-attack<\/a><\/p>\n<h3 style=\"text-align: justify;\"><\/h3>\n<h3 style=\"text-align: justify;\"><strong>D\u00e9sactiver le caniche<\/strong><\/h3>\n<p style=\"text-align: justify;\"><a href=\"https:\/\/www.linode.com\/docs\/security\/security-patches\/disabling-sslv3-for-poodle\">https:\/\/www.linode.com\/docs\/security\/security-patches\/disabling-sslv3-for-poodle<\/a><\/p>\n<p style=\"text-align: justify;\"><a href=\"http:\/\/askubuntu.com\/questions\/537196\/how-do-i-patch-workaround-sslv3-poodle-vulnerability-cve-2014-3566\">http:\/\/askubuntu.com\/questions\/537196\/how-do-i-patch-workaround-sslv3-poodle-vulnerability-cve-2014-3566<\/a><\/p>\n<p><a href=\"\/fr\/contactez-nous\/\">Prenez contact avec nous.<\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-18abb3a8 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"18abb3a8\" data-element_type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-20ff2b60\" data-id=\"20ff2b60\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-738ca7ed elementor-widget elementor-widget-heading\" data-id=\"738ca7ed\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Abonnez-vous pour les derni\u00e8res mises \u00e0 jour<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3ca92304 elementor-widget elementor-widget-shortcode\" data-id=\"3ca92304\" data-element_type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\">\t\t\t\t\t<script type=\"text\/javascript\">\n\t\t\t\t\t\tvar gCaptchaSibWidget;\n                        var onloadSibCallbackInvisible = function () {\n\n                            var element = document.getElementsByClassName('sib-default-btn');\n                            var countInvisible = 0;\n                            var indexArray = [];\n                            jQuery('.sib-default-btn').each(function (index, el) {\n                                if ((jQuery(el).attr('id') == \"invisible\")) {\n                                    indexArray[countInvisible] = index;\n                                    countInvisible++\n                                }\n                            });\n\n                            jQuery('.invi-recaptcha').each(function (index, el) {\n                                grecaptcha.render(element[indexArray[index]], {\n                                    'sitekey': jQuery(el).attr('data-sitekey'),\n                                    'callback': sibVerifyCallback,\n                                });\n                            });\n                        };\n\t\t\t\t\t<\/script>\n\t\t\t\t\t                <script src=\"https:\/\/www.google.com\/recaptcha\/api.js?onload=onloadSibCallbackInvisible&render=explicit\" async defer><\/script>\n\t\t\t\t\n\t\t\t<form id=\"sib_signup_form_1\" method=\"post\" class=\"sib_signup_form\" action=\"\">\n\t\t\t\t<div class=\"sib_loader\" style=\"display:none;\"><img\n\t\t\t\t\t\t\tsrc=\"https:\/\/www.railscarma.com\/wp-includes\/images\/spinner.gif\" alt=\"chargeur\"><\/div>\n\t\t\t\t<input type=\"hidden\" name=\"sib_form_action\" value=\"subscribe_form_submit\">\n\t\t\t\t<input type=\"hidden\" name=\"sib_form_id\" value=\"1\">\n                <input type=\"hidden\" name=\"sib_form_alert_notice\" value=\"Please fill out this field\">\n                <input type=\"hidden\" name=\"sib_form_invalid_email_notice\" value=\"Your email address is invalid\">\n                <input type=\"hidden\" name=\"sib_security\" value=\"d7f7626ab9\">\n\t\t\t\t<div class=\"sib_signup_box_inside_1\">\n\t\t\t\t\t<div style=\"\/*display:none*\/\" class=\"sib_msg_disp\">\n\t\t\t\t\t<\/div>\n                                            <div id=\"sib_captcha_invisible\" class=\"invi-recaptcha\" data-sitekey=\"6LdikOAaAAAAAJ6SWrrKVQrtw7TQpQAEnv0HS0G3\"><\/div>\n                    \t\t\t\t\t<p class=\"sib-email-area\">\r\n    <label class=\"sib-email-area\"><\/label>\r\n    <input type=\"email\" class=\"sib-email-area\" name=\"email\" required=\"required\" placeholder=\"Adresse e-mail\">\r\n<\/p>\r\n<p class=\"sib-NAME-area\">\r\n    <label class=\"sib-NAME-area\"><\/label>\r\n    <input type=\"text\" class=\"sib-NAME-area\" name=\"NAME\" placeholder=\"Nom\">\r\n<\/p>\r\n<p>\r\n    <input type=\"submit\" id=\"invisible\" class=\"sib-default-btn\" value=\"S&#039;abonner\">\r\n<\/p>\t\t\t\t<\/div>\n\t\t\t<input type=\"hidden\" name=\"trp-form-language\" value=\"fr\"\/><\/form>\n\t\t\t<style>\n\t\t\t\tform#sib_signup_form_1 p.sib-alert-message {\n    padding: 6px 12px;\n    margin-bottom: 20px;\n    border: 1px solid transparent;\n    border-radius: 4px;\n    -webkit-box-sizing: border-box;\n    -moz-box-sizing: border-box;\n    box-sizing: border-box;\n}\nform#sib_signup_form_1 p.sib-alert-message-error {\n    background-color: #f2dede;\n    border-color: #ebccd1;\n    color: #a94442;\n}\nform#sib_signup_form_1 p.sib-alert-message-success {\n    background-color: #dff0d8;\n    border-color: #d6e9c6;\n    color: #3c763d;\n}\nform#sib_signup_form_1 p.sib-alert-message-warning {\n    background-color: #fcf8e3;\n    border-color: #faebcc;\n    color: #8a6d3b;\n}\n\t\t\t<\/style>\n\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t  <div class=\"related-post slider\">\r\n        <div class=\"headline\">Articles Similaires<\/div>\r\n    <div class=\"post-list owl-carousel\">\r\n\r\n            <div class=\"item\">\r\n            <div class=\"thumb post_thumb\">\r\n    <a  title=\"Gemme de Kaminari\" href=\"https:\/\/www.railscarma.com\/fr\/blog\/articles-techniques\/joyau-kaminari\/?related_post_from=37277\">\r\n\r\n      <img decoding=\"async\" width=\"800\" height=\"300\" src=\"https:\/\/www.railscarma.com\/wp-content\/uploads\/2023\/04\/kaminari-gem.jpg\" class=\"attachment-full size-full wp-post-image\" alt=\"joyau kaminari\" srcset=\"https:\/\/www.railscarma.com\/wp-content\/uploads\/2023\/04\/kaminari-gem.jpg 800w, https:\/\/www.railscarma.com\/wp-content\/uploads\/2023\/04\/kaminari-gem-300x113.jpg 300w, https:\/\/www.railscarma.com\/wp-content\/uploads\/2023\/04\/kaminari-gem-768x288.jpg 768w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/>\r\n\r\n    <\/a>\r\n  <\/div>\r\n\r\n  <a class=\"title post_title\"  title=\"Gemme de Kaminari\" href=\"https:\/\/www.railscarma.com\/fr\/blog\/articles-techniques\/joyau-kaminari\/?related_post_from=37277\">\r\n        Gemme de Kaminari  <\/a>\r\n\r\n        <\/div>\r\n              <div class=\"item\">\r\n            <div class=\"thumb post_thumb\">\r\n    <a  title=\"Pourquoi engager des d\u00e9veloppeurs Ruby on Rails en 2026 ?\" href=\"https:\/\/www.railscarma.com\/fr\/blog\/ror\/pourquoi-embaucher-des-developpeurs-ruby-on-rails\/?related_post_from=30627\">\r\n\r\n      <img decoding=\"async\" width=\"800\" height=\"300\" src=\"https:\/\/www.railscarma.com\/wp-content\/uploads\/2019\/01\/why-to-hire-ruby-on-rails-developers-in-2022.jpg\" class=\"attachment-full size-full wp-post-image\" alt=\"pourquoi embaucher des d\u00e9veloppeurs Ruby on Rails en 2022\" srcset=\"https:\/\/www.railscarma.com\/wp-content\/uploads\/2019\/01\/why-to-hire-ruby-on-rails-developers-in-2022.jpg 800w, https:\/\/www.railscarma.com\/wp-content\/uploads\/2019\/01\/why-to-hire-ruby-on-rails-developers-in-2022-300x113.jpg 300w, https:\/\/www.railscarma.com\/wp-content\/uploads\/2019\/01\/why-to-hire-ruby-on-rails-developers-in-2022-768x288.jpg 768w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/>\r\n\r\n    <\/a>\r\n  <\/div>\r\n\r\n  <a class=\"title post_title\"  title=\"Pourquoi engager des d\u00e9veloppeurs Ruby on Rails en 2026 ?\" href=\"https:\/\/www.railscarma.com\/fr\/blog\/ror\/pourquoi-embaucher-des-developpeurs-ruby-on-rails\/?related_post_from=30627\">\r\n        Pourquoi engager des d\u00e9veloppeurs Ruby on Rails en 2026 ?  <\/a>\r\n\r\n        <\/div>\r\n              <div class=\"item\">\r\n            <div class=\"thumb post_thumb\">\r\n    <a  title=\"Importance de l&#039;architecture logicielle dans le d\u00e9veloppement de logiciels d&#039;entreprise\" href=\"https:\/\/www.railscarma.com\/fr\/blog\/ror\/importance-de-larchitecture-logicielle-dans-le-developpement-de-logiciels-dentreprise\/?related_post_from=36250\">\r\n\r\n      <img decoding=\"async\" width=\"800\" height=\"300\" src=\"https:\/\/www.railscarma.com\/wp-content\/uploads\/2022\/06\/Importance-of-Software-Architecture-in-enterprise-software-development.jpg\" class=\"attachment-full size-full wp-post-image\" alt=\"Importance de l&#039;architecture logicielle dans le d\u00e9veloppement de logiciels d&#039;entreprise\" srcset=\"https:\/\/www.railscarma.com\/wp-content\/uploads\/2022\/06\/Importance-of-Software-Architecture-in-enterprise-software-development.jpg 800w, https:\/\/www.railscarma.com\/wp-content\/uploads\/2022\/06\/Importance-of-Software-Architecture-in-enterprise-software-development-300x113.jpg 300w, https:\/\/www.railscarma.com\/wp-content\/uploads\/2022\/06\/Importance-of-Software-Architecture-in-enterprise-software-development-768x288.jpg 768w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/>\r\n\r\n    <\/a>\r\n  <\/div>\r\n\r\n  <a class=\"title post_title\"  title=\"Importance de l&#039;architecture logicielle dans le d\u00e9veloppement de logiciels d&#039;entreprise\" href=\"https:\/\/www.railscarma.com\/fr\/blog\/ror\/importance-de-larchitecture-logicielle-dans-le-developpement-de-logiciels-dentreprise\/?related_post_from=36250\">\r\n        Importance de l&#039;architecture logicielle dans le d\u00e9veloppement de logiciels d&#039;entreprise  <\/a>\r\n\r\n        <\/div>\r\n              <div class=\"item\">\r\n            <div class=\"thumb post_thumb\">\r\n    <a  title=\"Ruby IDE\u00a0: les meilleurs IDE pour le d\u00e9veloppement Ruby on Rails\" href=\"https:\/\/www.railscarma.com\/fr\/blog\/ror\/ruby-ide-les-meilleures-idees-pour-le-developpement-de-ruby-on-rails\/?related_post_from=36125\">\r\n\r\n      <img decoding=\"async\" width=\"800\" height=\"300\" src=\"https:\/\/www.railscarma.com\/wp-content\/uploads\/2022\/01\/BEST-IDES-FOR-RUBY-ON-RAILS-DEVELOPMENT.jpg\" class=\"attachment-full size-full wp-post-image\" alt=\"MEILLEURES ID\u00c9ES POUR LE D\u00c9VELOPPEMENT DE RUBY ON RAILS\" srcset=\"https:\/\/www.railscarma.com\/wp-content\/uploads\/2022\/01\/BEST-IDES-FOR-RUBY-ON-RAILS-DEVELOPMENT.jpg 800w, https:\/\/www.railscarma.com\/wp-content\/uploads\/2022\/01\/BEST-IDES-FOR-RUBY-ON-RAILS-DEVELOPMENT-300x113.jpg 300w, https:\/\/www.railscarma.com\/wp-content\/uploads\/2022\/01\/BEST-IDES-FOR-RUBY-ON-RAILS-DEVELOPMENT-768x288.jpg 768w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/>\r\n\r\n    <\/a>\r\n  <\/div>\r\n\r\n  <a class=\"title post_title\"  title=\"Ruby IDE\u00a0: les meilleurs IDE pour le d\u00e9veloppement Ruby on Rails\" href=\"https:\/\/www.railscarma.com\/fr\/blog\/ror\/ruby-ide-les-meilleures-idees-pour-le-developpement-de-ruby-on-rails\/?related_post_from=36125\">\r\n        Ruby IDE\u00a0: les meilleurs IDE pour le d\u00e9veloppement Ruby on Rails  <\/a>\r\n\r\n        <\/div>\r\n      \r\n  <\/div>\r\n\r\n  <script>\r\n      <\/script>\r\n  <style>\r\n    .related-post {}\r\n\r\n    .related-post .post-list {\r\n      text-align: left;\r\n          }\r\n\r\n    .related-post .post-list .item {\r\n      margin: 10px;\r\n      padding: 10px;\r\n          }\r\n\r\n    .related-post .headline {\r\n      font-size: 14px !important;\r\n      color: #999999 !important;\r\n          }\r\n\r\n    .related-post .post-list .item .post_thumb {\r\n      max-height: 220px;\r\n      margin: 10px 0px;\r\n      padding: 0px;\r\n      display: block;\r\n          }\r\n\r\n    .related-post .post-list .item .post_title {\r\n      font-size: 14px;\r\n      color: #000000;\r\n      margin: 10px 0px;\r\n      padding: 0px;\r\n      display: block;\r\n      text-decoration: none;\r\n          }\r\n\r\n    .related-post .post-list .item .post_excerpt {\r\n      font-size: 12px;\r\n      color: #3f3f3f;\r\n      margin: 10px 0px;\r\n      padding: 0px;\r\n      display: block;\r\n      text-decoration: none;\r\n          }\r\n\r\n    .related-post .owl-dots .owl-dot {\r\n          }\r\n\r\n      <\/style>\r\n      <script>\r\n      jQuery(document).ready(function($) {\r\n        $(\".related-post .post-list\").owlCarousel({\r\n          items: 2,\r\n          responsiveClass: true,\r\n          responsive: {\r\n            0: {\r\n              items: 1,\r\n            },\r\n            768: {\r\n              items: 2,\r\n            },\r\n            1200: {\r\n              items: 2,\r\n            }\r\n          },\r\n                      rewind: true,\r\n                                loop: true,\r\n                                center: false,\r\n                                autoplay: true,\r\n            autoplayHoverPause: true,\r\n                                nav: true,\r\n            navSpeed: 1000,\r\n            navText: ['<i class=\"fas fa-chevron-left\"><\/i>', '<i class=\"fas fa-chevron-right\"><\/i>'],\r\n                                dots: false,\r\n            dotsSpeed: 1200,\r\n                                                    rtl: false,\r\n          \r\n        });\r\n      });\r\n    <\/script>\r\n  <\/div>","protected":false},"excerpt":{"rendered":"<p>Poodle&nbsp;is a breed of dog with legs that resembles cotton candies. It is intelligent and a regular staple at dog shows. Even the most friendly dogs have the propensity to bite. Now we see all kinds of security alerts and snafus likes heartbleed and shell shock!!! The latest in addition is POODLE. This is all &hellip;<\/p>\n<p class=\"read-more\"> <a class=\"\" href=\"https:\/\/www.railscarma.com\/fr\/blog\/ruby-regex-match-guide-with-examples\/\"> <span class=\"screen-reader-text\">Guide de correspondance des expressions rationnelles en Ruby (2026) avec exemples<\/span> Lire la suite \u00bb<\/a><\/p>","protected":false},"author":1,"featured_media":32075,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[384],"tags":[609,513,610],"class_list":["post-6492","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technical-articles","tag-security-threats","tag-ssl","tag-sslv3"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Poodle: SSL Security Threat Explored - RailsCarma Blog<\/title>\n<meta name=\"description\" content=\"The POODLE attack takes advantage of the protocol version negotiation feature built into SSL\/TLS to force the use of SSL 3.0 and then uses this new vulnerability to decrypt select content within the SSL session\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.railscarma.com\/fr\/blog\/articles-techniques\/menace-de-securite-ssl-caniche-exploree-2\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Poodle: SSL Security Threat Explored - RailsCarma Blog\" \/>\n<meta property=\"og:description\" content=\"The POODLE attack takes advantage of the protocol version negotiation feature built into SSL\/TLS to force the use of SSL 3.0 and then uses this new vulnerability to decrypt select content within the SSL session\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.railscarma.com\/fr\/blog\/articles-techniques\/menace-de-securite-ssl-caniche-exploree-2\/\" \/>\n<meta property=\"og:site_name\" content=\"RailsCarma - Ruby on Rails Development Company specializing in Offshore Development\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/RailsCarma\/\" \/>\n<meta property=\"article:published_time\" content=\"2014-11-30T07:29:11+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-08-30T07:32:51+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.railscarma.com\/wp-content\/uploads\/2014\/11\/POODLE-SSLv3-RC.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"644\" \/>\n\t<meta property=\"og:image:height\" content=\"292\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@railscarma\" \/>\n<meta name=\"twitter:site\" content=\"@railscarma\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/www.railscarma.com\/#\/schema\/person\/5f2228a2dec7549056e709de6eb85d21\"},\"headline\":\"Poodle \u2013 SSL Security Threat Explored\",\"datePublished\":\"2014-11-30T07:29:11+00:00\",\"dateModified\":\"2022-08-30T07:32:51+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/\"},\"wordCount\":1085,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.railscarma.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.railscarma.com\/wp-content\/uploads\/2014\/11\/POODLE-SSLv3-RC.jpg\",\"keywords\":[\"security threats\",\"SSL\",\"sslv3\"],\"articleSection\":[\"Technical Articles\"],\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/\",\"url\":\"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/\",\"name\":\"Poodle: SSL Security Threat Explored - RailsCarma Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.railscarma.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.railscarma.com\/wp-content\/uploads\/2014\/11\/POODLE-SSLv3-RC.jpg\",\"datePublished\":\"2014-11-30T07:29:11+00:00\",\"dateModified\":\"2022-08-30T07:32:51+00:00\",\"description\":\"The POODLE attack takes advantage of the protocol version negotiation feature built into SSL\/TLS to force the use of SSL 3.0 and then uses this new vulnerability to decrypt select content within the SSL session\",\"breadcrumb\":{\"@id\":\"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/#primaryimage\",\"url\":\"https:\/\/www.railscarma.com\/wp-content\/uploads\/2014\/11\/POODLE-SSLv3-RC.jpg\",\"contentUrl\":\"https:\/\/www.railscarma.com\/wp-content\/uploads\/2014\/11\/POODLE-SSLv3-RC.jpg\",\"width\":644,\"height\":292},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.railscarma.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Poodle \u2013 SSL Security Threat Explored\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.railscarma.com\/#website\",\"url\":\"https:\/\/www.railscarma.com\/\",\"name\":\"RailsCarma - Ruby on Rails Development Company specializing in Offshore Development\",\"description\":\"RailsCarma is a Ruby on Rails Development Company in Bangalore. We specialize in Offshore Ruby on Rails Development based out in USA and India. Hire experienced Ruby on Rails developers for the ultimate Web Experience.\",\"publisher\":{\"@id\":\"https:\/\/www.railscarma.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.railscarma.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.railscarma.com\/#organization\",\"name\":\"RailsCarma\",\"url\":\"https:\/\/www.railscarma.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/www.railscarma.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.railscarma.com\/wp-content\/uploads\/2020\/08\/railscarma_logo.png\",\"contentUrl\":\"https:\/\/www.railscarma.com\/wp-content\/uploads\/2020\/08\/railscarma_logo.png\",\"width\":200,\"height\":46,\"caption\":\"RailsCarma\"},\"image\":{\"@id\":\"https:\/\/www.railscarma.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/RailsCarma\/\",\"https:\/\/x.com\/railscarma\",\"https:\/\/www.linkedin.com\/company\/railscarma\/\",\"https:\/\/myspace.com\/railscarma\",\"https:\/\/in.pinterest.com\/railscarma\/\",\"https:\/\/www.youtube.com\/channel\/UCx3Wil-aAnDARuatTEyMdpg\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.railscarma.com\/#\/schema\/person\/5f2228a2dec7549056e709de6eb85d21\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/www.railscarma.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/308867ca6c81f3aba146080c601000087180326f752c4116849ea9f514c6a4fa?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/308867ca6c81f3aba146080c601000087180326f752c4116849ea9f514c6a4fa?s=96&d=mm&r=g\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/www.railscarma.com\/hire-ruby-on-rails-developer\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Poodle\u00a0:\u00a0menace de s\u00e9curit\u00e9 SSL explor\u00e9e - RailsCarma Blog","description":"L&#039;attaque POODLE profite de la fonctionnalit\u00e9 de n\u00e9gociation de version de protocole int\u00e9gr\u00e9e \u00e0 SSL\/TLS pour forcer l&#039;utilisation de SSL 3.0, puis utilise cette nouvelle vuln\u00e9rabilit\u00e9 pour d\u00e9crypter certains contenus au sein de la session SSL.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.railscarma.com\/fr\/blog\/articles-techniques\/menace-de-securite-ssl-caniche-exploree-2\/","og_locale":"fr_FR","og_type":"article","og_title":"Poodle: SSL Security Threat Explored - RailsCarma Blog","og_description":"The POODLE attack takes advantage of the protocol version negotiation feature built into SSL\/TLS to force the use of SSL 3.0 and then uses this new vulnerability to decrypt select content within the SSL session","og_url":"https:\/\/www.railscarma.com\/fr\/blog\/articles-techniques\/menace-de-securite-ssl-caniche-exploree-2\/","og_site_name":"RailsCarma - Ruby on Rails Development Company specializing in Offshore Development","article_publisher":"https:\/\/www.facebook.com\/RailsCarma\/","article_published_time":"2014-11-30T07:29:11+00:00","article_modified_time":"2022-08-30T07:32:51+00:00","og_image":[{"width":644,"height":292,"url":"https:\/\/www.railscarma.com\/wp-content\/uploads\/2014\/11\/POODLE-SSLv3-RC.jpg","type":"image\/jpeg"}],"author":"admin","twitter_card":"summary_large_image","twitter_creator":"@railscarma","twitter_site":"@railscarma","twitter_misc":{"\u00c9crit par":"admin","Dur\u00e9e de lecture estim\u00e9e":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/#article","isPartOf":{"@id":"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/"},"author":{"name":"admin","@id":"https:\/\/www.railscarma.com\/#\/schema\/person\/5f2228a2dec7549056e709de6eb85d21"},"headline":"Poodle \u2013 SSL Security Threat Explored","datePublished":"2014-11-30T07:29:11+00:00","dateModified":"2022-08-30T07:32:51+00:00","mainEntityOfPage":{"@id":"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/"},"wordCount":1085,"commentCount":0,"publisher":{"@id":"https:\/\/www.railscarma.com\/#organization"},"image":{"@id":"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/#primaryimage"},"thumbnailUrl":"https:\/\/www.railscarma.com\/wp-content\/uploads\/2014\/11\/POODLE-SSLv3-RC.jpg","keywords":["security threats","SSL","sslv3"],"articleSection":["Technical Articles"],"inLanguage":"fr-FR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/","url":"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/","name":"Poodle\u00a0:\u00a0menace de s\u00e9curit\u00e9 SSL explor\u00e9e - RailsCarma Blog","isPartOf":{"@id":"https:\/\/www.railscarma.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/#primaryimage"},"image":{"@id":"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/#primaryimage"},"thumbnailUrl":"https:\/\/www.railscarma.com\/wp-content\/uploads\/2014\/11\/POODLE-SSLv3-RC.jpg","datePublished":"2014-11-30T07:29:11+00:00","dateModified":"2022-08-30T07:32:51+00:00","description":"L&#039;attaque POODLE profite de la fonctionnalit\u00e9 de n\u00e9gociation de version de protocole int\u00e9gr\u00e9e \u00e0 SSL\/TLS pour forcer l&#039;utilisation de SSL 3.0, puis utilise cette nouvelle vuln\u00e9rabilit\u00e9 pour d\u00e9crypter certains contenus au sein de la session SSL.","breadcrumb":{"@id":"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/#primaryimage","url":"https:\/\/www.railscarma.com\/wp-content\/uploads\/2014\/11\/POODLE-SSLv3-RC.jpg","contentUrl":"https:\/\/www.railscarma.com\/wp-content\/uploads\/2014\/11\/POODLE-SSLv3-RC.jpg","width":644,"height":292},{"@type":"BreadcrumbList","@id":"https:\/\/www.railscarma.com\/blog\/technical-articles\/poodle-ssl-security-threat-explored-2\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.railscarma.com\/"},{"@type":"ListItem","position":2,"name":"Poodle \u2013 SSL Security Threat Explored"}]},{"@type":"WebSite","@id":"https:\/\/www.railscarma.com\/#website","url":"https:\/\/www.railscarma.com\/","name":"RailsCarma - Soci\u00e9t\u00e9 de d\u00e9veloppement Ruby on Rails sp\u00e9cialis\u00e9e dans le d\u00e9veloppement offshore","description":"RailsCarma est une soci\u00e9t\u00e9 de d\u00e9veloppement Ruby on Rails \u00e0 Bangalore. Nous sommes sp\u00e9cialis\u00e9s dans le d\u00e9veloppement offshore Ruby on Rails, bas\u00e9s aux \u00c9tats-Unis et en Inde. Embauchez des d\u00e9veloppeurs Ruby on Rails exp\u00e9riment\u00e9s pour une exp\u00e9rience Web ultime.","publisher":{"@id":"https:\/\/www.railscarma.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.railscarma.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/www.railscarma.com\/#organization","name":"RailsCarma","url":"https:\/\/www.railscarma.com\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.railscarma.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.railscarma.com\/wp-content\/uploads\/2020\/08\/railscarma_logo.png","contentUrl":"https:\/\/www.railscarma.com\/wp-content\/uploads\/2020\/08\/railscarma_logo.png","width":200,"height":46,"caption":"RailsCarma"},"image":{"@id":"https:\/\/www.railscarma.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/RailsCarma\/","https:\/\/x.com\/railscarma","https:\/\/www.linkedin.com\/company\/railscarma\/","https:\/\/myspace.com\/railscarma","https:\/\/in.pinterest.com\/railscarma\/","https:\/\/www.youtube.com\/channel\/UCx3Wil-aAnDARuatTEyMdpg"]},{"@type":"Person","@id":"https:\/\/www.railscarma.com\/#\/schema\/person\/5f2228a2dec7549056e709de6eb85d21","name":"administrateur","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.railscarma.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/308867ca6c81f3aba146080c601000087180326f752c4116849ea9f514c6a4fa?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/308867ca6c81f3aba146080c601000087180326f752c4116849ea9f514c6a4fa?s=96&d=mm&r=g","caption":"admin"},"sameAs":["https:\/\/www.railscarma.com\/hire-ruby-on-rails-developer\/"]}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.railscarma.com\/fr\/wp-json\/wp\/v2\/posts\/6492","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.railscarma.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.railscarma.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.railscarma.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.railscarma.com\/fr\/wp-json\/wp\/v2\/comments?post=6492"}],"version-history":[{"count":0,"href":"https:\/\/www.railscarma.com\/fr\/wp-json\/wp\/v2\/posts\/6492\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.railscarma.com\/fr\/wp-json\/wp\/v2\/media\/32075"}],"wp:attachment":[{"href":"https:\/\/www.railscarma.com\/fr\/wp-json\/wp\/v2\/media?parent=6492"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.railscarma.com\/fr\/wp-json\/wp\/v2\/categories?post=6492"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.railscarma.com\/fr\/wp-json\/wp\/v2\/tags?post=6492"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}