Web Hack List

Top 10 winner

BEAST

A first-person account of building BEAST. Rizzo's chosen-boundary attack on SSL/TLS CBC was reversed to suit browsers, which needed two records inside one cookie-bearing request; WebSockets and then a Java applet supplied that primitive. A Java same-origin-policy bypass loaded the agent, and optimisation cut decryption of long live cookies to minutes.

Record

Researcher
Thai Duong
Published by
Blogger
Date
Topic
Crypto

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Thai Duong, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .