Web Hack List

Collected research

Man-in-the-Browser-Cache: Persisting HTTPS Attacks via Browser Cache Poisoning

Clicking through a single invalid-certificate warning lets a one-time man-in-the-middle replace cached scripts, images or an HTML5 AppCache manifest with long-lived malicious copies. The poisoned resources keep running in later, correctly secured HTTPS sessions until the cache is cleared, and extension-injected scripts spread the poisoning to every site visited.

Record

Researcher
Yaoqi Jia, Yue Chen, Xinshu Dong, Prateek Saxena, Jian Mao and Zhenkai Liang
Published by
doi.org
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Yaoqi Jia, Yue Chen, Xinshu Dong, Prateek Saxena, Jian Mao and Zhenkai Liang, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .