Top 10 winner
CRIME
New Attack Uses SSL/TLS Information Leak to Hijack HTTPS Sessions
Threatpost's pre-disclosure report on CRIME: Rizzo and Duong found an optional TLS feature that leaks enough about encrypted traffic to recover session cookies, in every TLS version including 1.2 and whatever the cipher suite. With a man-in-the-middle position and JavaScript in the victim's browser they decrypt cookies; the RC4 switch that stopped BEAST does not help.
Record
- Document
- New Attack Uses SSL/TLS Information Leak to Hijack HTTPS Sessions
- Researcher
- Dennis Fisher
- Published by
- threatpost.com
- Topic
- Crypto
In the archive
Related sources
- Crack in Internet's foundation of trust allows HTTPS session hijacking
- Compression and Information Leakage of Plaintext Whitepaper
Tags
This page is the archive's own catalogue record. The research is the work of Dennis Fisher, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .