Poodle and EAP?

A.L.M.Buxey at lboro.ac.uk A.L.M.Buxey at lboro.ac.uk
Mon Oct 20 14:31:47 CEST 2014


Hi,

> Alan has pointed out that SSLv3 is disabled, but in any event
> exploiting POODLE requires forcing the client to make variable
> content SSLv3 requests. It's tricky to see how that could be
> achieved with EAP clients.

well, I wouldnt be surpised with some clients  ;-)

alan


More information about the Freeradius-Users mailing list