Web Hack List

Top 10 winner

Attacking HTTPS with Cache Injection

Four attacks on where secure protocols put their data. A web page fingerprints, logs into and XSSes home routers across eight brands to steal the WPA key and geolocate it; cached JavaScript injected on open Wi-Fi compromises later HTTPS sessions; a frame leak reads scrollbar position to extract Facebook profile facts through its dark-div defence; and tapjacking abuses mobile zoom and URL-bar hiding.

Record

Researcher
Elie Bursztein, Baptiste Gourdin, Gustav Rydstedt and Dan Boneh
Published by
media.blackhat.com
Date
Format
Recording
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Elie Bursztein, Baptiste Gourdin, Gustav Rydstedt and Dan Boneh, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .