Collected research
Opossum Attack
Cross-protocol desynchronisation against services that offer both implicit TLS on a dedicated port and opportunistic TLS upgrade. A man-in-the-middle splices the client's TLS connection onto its own upgraded plaintext connection, leaving client and server one message apart, which gives resource confusion, session fixation and self-XSS escalation.
Record
- Researcher
- Robert Merget, Nurullah Erinola, Marcel Maehren, Lukas Knittel, Sven Hebrok, Marcus Brinkmann, Juraj Somorovsky and Jörg Schwenk
- Published by
- opossum-attack.com
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Robert Merget, Nurullah Erinola, Marcel Maehren, Lukas Knittel, Sven Hebrok, Marcus Brinkmann, Juraj Somorovsky and Jörg Schwenk, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .