Web Hack List

Collected research

Cross-Origin Web Attacks via HTTP/2 Server Push and Signed HTTP Exchange

HTTP/2 server push and Signed HTTP Exchange authorise content by the certificate's subject alternative names rather than by the URI origin, so where a certificate is shared an off-path attacker can push or sign responses for any domain it covers. The result is cross-origin XSS, cookie manipulation and malicious downloads.

Record

Researcher
Pinji Chen, Jianjun Chen, Mingming Zhang, Qi Wang, Yiming Zhang, Mingwei Xu and Haixin Duan
Published by
NDSS Symposium
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Pinji Chen, Jianjun Chen, Mingming Zhang, Qi Wang, Yiming Zhang, Mingwei Xu and Haixin Duan, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .