Collected research
Breaking Out HSTS (and HPKP) on Firefox, IE/Edge and (Possibly) Chrome
Black Hat Europe 2017
Firefox, IE/Edge and Chrome store HSTS and HPKP state in ways an attacker can remotely overwrite, so a site that should be locked to HTTPS can be pushed back to plaintext. A sniffing or man-in-the-middle attacker on the same network then reads credentials from sites that had enforced HTTPS.
Record
- Document
- Black Hat Europe 2017
- Published by
- blackhat.com
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of blackhat.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .