Collected research
Postcards from the Post-HTTP World: Amplification of HTTPS Vulnerabilities in the Web Ecosystem
A crawl of the Alexa top 10k plus 90,816 dependency and sub-domain hosts maps still-exploitable TLS flaws such as ROBOT, DROWN, POODLE-TLS and Heartbleed onto attack trees, then measures the web-application damage. 898 sites become fully compromisable, 412 can have every session cookie stolen and 543 accept forced cookies, usually via a vulnerable related domain or script host.
Record
- Researcher
- Stefano Calzavara, Riccardo Focardi, Matus Nemec, Alvise Rabitti and Marco Squarcina
- Published by
- ieeexplore.ieee.org
- Topic
- HTTP
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Stefano Calzavara, Riccardo Focardi, Matus Nemec, Alvise Rabitti and Marco Squarcina, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .