Web Hack List

Collected research

Opossum Attack

Cross-protocol desynchronisation against services that offer both implicit TLS on a dedicated port and opportunistic TLS upgrade. A man-in-the-middle splices the client's TLS connection onto its own upgraded plaintext connection, leaving client and server one message apart, which gives resource confusion, session fixation and self-XSS escalation.

Record

Researcher
Robert Merget, Nurullah Erinola, Marcel Maehren, Lukas Knittel, Sven Hebrok, Marcus Brinkmann, Juraj Somorovsky and Jörg Schwenk
Published by
opossum-attack.com
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Robert Merget, Nurullah Erinola, Marcel Maehren, Lukas Knittel, Sven Hebrok, Marcus Brinkmann, Juraj Somorovsky and Jörg Schwenk, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .