Collected research
Man-in-the-Browser-Cache: Persisting HTTPS Attacks via Browser Cache Poisoning
Clicking through a single invalid-certificate warning lets a one-time man-in-the-middle replace cached scripts, images or an HTML5 AppCache manifest with long-lived malicious copies. The poisoned resources keep running in later, correctly secured HTTPS sessions until the cache is cleared, and extension-injected scripts spread the poisoning to every site visited.
Record
- Researcher
- Yaoqi Jia, Yue Chen, Xinshu Dong, Prateek Saxena, Jian Mao and Zhenkai Liang
- Published by
- doi.org
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Yaoqi Jia, Yue Chen, Xinshu Dong, Prateek Saxena, Jian Mao and Zhenkai Liang, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .