Web Hack List

Later archive addition

Hijacking browser TLS traffic through Client Domain Hooking

The article introduces Client Domain Hooking, a MITM technique that uses one intercepted clear-text request to keep a browser communicating through an attacker-controlled domain and reverse proxy while preserving trusted TLS. It also announces a study finding that 80% of the reviewed browser-based applications lacked HSTS.

Record

Researcher
Piotr Duszyński
Published by
duszynski.eu
Date

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Piotr Duszyński, first published at the original source. Preserved copies are kept so the citation survives its host.