CBC padding oracle TL;DR: Server distinguishes valid from invalid PKCS#7 padding; that one bit decrypts entire ciphertexts. Stub — to be filled in. What it is TODO Preconditions / where it applies TODO Technique TODO Detection and defence TODO References TODO