The 2016 Pwnie Nominee For Best Branding

SSLv2 Cryto attack (CVE-2016-0800)

Credit: Aviram et al

In this attack, mid-90’s code that everybody supported (SSLv2) but nobody thought anybody used, turned out to be vulnerable. This allowed attackers to decrypt SSL sessions for servers which supported this old protocol. In a change from the ordinary, this website, along with catchy logo was created by a team of academic researchers. I always thought they were above such things. I guess when you have a paper with 15 authors, at least one wants to be like the heartbleed guys.

SSLv2 Cryto attack
