(this is a follow-on paper to Vaudenay02 which doesn't seem available online) How to break CBC encryption using certain common padding schemes given a "padding oracle", a node that tells you whether or not a given ciphertext corresponds to a well-padded plaintext. Breaking CBC Encryption for Fun and Profit |