Web Hack List

Collected research

STEK Sharing is Not Caring: Bypassing TLS Authentication in Web Servers using Session Tickets

Web servers that share one TLS session ticket encryption key across their virtual hosts let a ticket issued by one host be resumed against another, confusing which host and which client a session belongs to. That bypasses client authentication on four widely used servers and server authentication at six clusters of hosting providers.

Record

Researcher
Sven Hebrok, Tim Leonhard Storm, Felix Matthias Cramer, Maximilian Radoy and Juraj Somorovsky
Published by
usenix.org
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Sven Hebrok, Tim Leonhard Storm, Felix Matthias Cramer, Maximilian Radoy and Juraj Somorovsky, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .