Web Hack List

Collected research

Breaking HTTPS with BGP Hijacking

BGP prefix hijacks can be kept local to a few autonomous systems, so the victim sees no latency change and public looking glasses show nothing. An attacker hijacks the victim's prefix near a certificate authority for the few minutes of domain validation, passes the WHOIS, HTTP or DNS check and walks away with a globally valid TLS certificate for machine-in-the-middle use.

Record

Researcher
Artyom Gavrichenkov
Published by
blackhat.com
Format
Recording
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Artyom Gavrichenkov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .