<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>CBC Padding Oracles in 2025 with Wade King</title>
        <link>https://video.infosec.exchange/videos/watch/38b1aeee-fda2-4eef-aed2-3e383c871192</link>
        <description>CBC padding oracles are supposed to be “fixed,” but attackers are still using them to break real systems and take over accounts. In this BSides Vancouver Island talk, security researcher Wade King walks through how classic CBC padding oracle attacks work, then shows new techniques that bypass “hardened” implementations by abusing how applications read and validate decrypted data. You’ll see how subtle crypto mistakes in legacy systems and token-based authentication can quietly turn into full account takeover. This session is ideal for blue and red teamers, penetration testers, AppSec engineers, and security architects dealing with legacy crypto, custom tokens, or encryption in web apps and APIs. Key topics include: How CBC mode and padding actually interact at the byte level, How classic CBC padding oracle attacks work in practice, “Double ciphertext” tricks that revive padding oracles even with unified error messages, Recovering first-block plaintext and IVs from structured tokens (like password reset links), How weak validation, predictable IDs, and automation lead to real-world account takeover on a gambling platform, Practical guidance for migrating to authenticated encryption (AES‑GCM) or adding HMAC protection around existing CBC schemes, If you work on application security, pen testing, or crypto in production systems, this talk will sharpen how you think about “legacy but still deployed” encryption. This session was recorded live at BSides Vancouver Island 2025 in Victoria, BC at the Victoria Conference Centre. 📣 BSides Vancouver Island 2026 Conference Join us on Friday, September 25, 2026 Victoria Conference Centre, Victoria, BC 🎤 Call for Presenters (CFP) — Deadline August 14, 2026 https://www.bsidesvi.com/cfp 🤝 Sponsorship Opportunities — Deadline August 14, 2026 https://www.bsidesvi.com/cfs 💬 Join the Community Slack https://communityinviter.com/apps/visrs/visrs Subscribe for more cybersecurity talks, AppSec deep dives, and crypto/security content from BSides Vancouver Island. #CBCCrypto #PaddingOracle #AppSec #PenTesting #BlueTeam #RedTeam #BSidesVI #BSidesVancouverIsland #VictoriaBC #CyberSecurity #InfoSec #SecurityConference #CryptoSecurity</description>
        <lastBuildDate>Wed, 20 May 2026 22:13:46 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>PeerTube - https://video.infosec.exchange</generator>
        <image>
            <title>CBC Padding Oracles in 2025 with Wade King</title>
            <url>https://video.infosec.exchange/client/assets/images/icons/icon-1500x1500.png</url>
            <link>https://video.infosec.exchange/videos/watch/38b1aeee-fda2-4eef-aed2-3e383c871192</link>
        </image>
        <copyright>All rights reserved, unless otherwise specified in the terms specified at https://video.infosec.exchange/about and potential licenses granted by each content's rightholder.</copyright>
        <atom:link href="https://video.infosec.exchange/feeds/video-comments.xml?videoId=38b1aeee-fda2-4eef-aed2-3e383c871192" rel="self" type="application/rss+xml"/>
    </channel>
</rss>