Top 10 winner
Attacking HTTPS with Cache Injection
Four attacks on where secure protocols put their data. A web page fingerprints, logs into and XSSes home routers across eight brands to steal the WPA key and geolocate it; cached JavaScript injected on open Wi-Fi compromises later HTTPS sessions; a frame leak reads scrollbar position to extract Facebook profile facts through its dark-div defence; and tapjacking abuses mobile zoom and URL-bar hiding.
Record
- Researcher
- Elie Bursztein, Baptiste Gourdin, Gustav Rydstedt and Dan Boneh
- Published by
- media.blackhat.com
- Date
- Format
- Recording
- Topic
- HTTP
In the archive
Related sources
- Bad Memories Whitepaper
- Tapjacking: owning smartphone browsers Recording
- Breaking into a WPA network with a webpage Recording
Tags
This page is the archive's own catalogue record. The research is the work of Elie Bursztein, Baptiste Gourdin, Gustav Rydstedt and Dan Boneh, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .