Collected research
STEK Sharing is Not Caring: Bypassing TLS Authentication in Web Servers using Session Tickets
Web servers that share one TLS session ticket encryption key across their virtual hosts let a ticket issued by one host be resumed against another, confusing which host and which client a session belongs to. That bypasses client authentication on four widely used servers and server authentication at six clusters of hosting providers.
Record
- Researcher
- Sven Hebrok, Tim Leonhard Storm, Felix Matthias Cramer, Maximilian Radoy and Juraj Somorovsky
- Published by
- usenix.org
- Topic
- Identity
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Sven Hebrok, Tim Leonhard Storm, Felix Matthias Cramer, Maximilian Radoy and Juraj Somorovsky, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .