Web Hack List

Collected research

Same Origin Spoofing to Attack Client Certificate Sessions

An Attack on SSL Client Certificates

Shows SSL client certificates do not stop a server-impersonating attacker. Mallory completes a handshake without validating Alice's certificate, returns a page holding attacker script plus an iframe to the real site, then closes the connection so the iframe renegotiates legitimately. Same-origin access from the injected script then reads the mutually authenticated frame.

Record

Document
An Attack on SSL Client Certificates
Researcher
Tom Ritter
Published by
isecpartners.com
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Tom Ritter, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .