Breaking CBC Encryption for Fun and Profit

Breaking CBC Encryption for Fun and Profit
by bucy at 5:07 pm EDT, Oct 13, 2003

(this is a follow-on paper to Vaudenay02 which doesn't seem available online)

How to break CBC encryption using certain common padding schemes given a "padding oracle", a node that tells you whether or not a given ciphertext corresponds to a well-padded plaintext.

