Collected research
Same Origin Spoofing to Attack Client Certificate Sessions
An Attack on SSL Client Certificates
Shows SSL client certificates do not stop a server-impersonating attacker. Mallory completes a handshake without validating Alice's certificate, returns a page holding attacker script plus an iframe to the real site, then closes the connection so the iframe renegotiates legitimately. Same-origin access from the injected script then reads the mutually authenticated frame.
Record
- Document
- An Attack on SSL Client Certificates
- Researcher
- Tom Ritter
- Published by
- isecpartners.com
- Topic
- Identity
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Tom Ritter, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .