Web Hack List

Collected research

MitM Attack by Name Collision: Cause Analysis and Vulnerability Assessment in the New gTLD Era

Study of WPAD proxy-discovery queries for internal namespaces that leak to the public DNS root, which became exploitable once the same strings were delegated as new gTLDs. Registering one such domain lets an attacker serve a proxy configuration and silently route a victim's whole web session through a man-in-the-middle proxy.

Record

Researcher
Qi Alfred Chen, Eric Osterweil, Matthew Thomas and Z. Morley Mao
Published by
ieee-security.org
Format
Whitepaper
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Qi Alfred Chen, Eric Osterweil, Matthew Thomas and Z. Morley Mao, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .