Web Hack List

Collected research

MITM Attacks on HTTPS: Another Perspective

A TLS certificate authenticates names, not hosts, ports or protocols, so a man in the middle can redirect a victim's connection for one host to another whose certificate covers the same name. Any control over that second host, an XSS, a file upload, a reflecting SMTP service or a permissive crossdomain.xml, becomes script execution or content substitution in the first host's origin.

Record

Researcher
GreenD0g
Published by
Slideshare
Date
Format
Slides
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of GreenD0g, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .