Collected research
Crippling HTTPS with Unholy PAC
Black Hat USA 2016
An attacker on a shared network forces a victim's browser or OS to load a hostile proxy auto-config file, whose JavaScript is handed the full URL of every request including HTTPS ones, leaking paths and the credentials or session tokens carried in them.
Record
- Document
- Black Hat USA 2016
- Published by
- blackhat.com
- Topic
- HTTP
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of blackhat.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .