Collected research
MITM Attacks on HTTPS: Another Perspective
A TLS certificate authenticates names, not hosts, ports or protocols, so a man in the middle can redirect a victim's connection for one host to another whose certificate covers the same name. Any control over that second host, an XSS, a file upload, a reflecting SMTP service or a permissive crossdomain.xml, becomes script execution or content substitution in the first host's origin.
Record
- Researcher
- GreenD0g
- Published by
- Slideshare
- Date
- Format
- Slides
- Topic
- HTTP
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of GreenD0g, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .