Web Hack List

Collected research

Breaking Out HSTS (and HPKP) on Firefox, IE/Edge and (Possibly) Chrome

Black Hat Europe 2017

Firefox, IE/Edge and Chrome store HSTS and HPKP state in ways an attacker can remotely overwrite, so a site that should be locked to HTTPS can be pushed back to plaintext. A sniffing or man-in-the-middle attacker on the same network then reads credentials from sites that had enforced HTTPS.

Record

Document
Black Hat Europe 2017
Published by
blackhat.com
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of blackhat.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .