Web Hack List

Collected research

Truncating TLS Connections to Violate Beliefs in Web Applications

TLS truncation lets an attacker cut off the tail of a response so browser and server end up disagreeing about what completed. The authors turned that desynchronisation into working attacks: casting votes on behalf of honest voters in the Helios e-voting system, taking full control of Microsoft Live accounts, and gaining temporary access to Google accounts.

Record

Researcher
Ben Smyth and Alfredo Pironti
Published by
usenix.org
Topic
Crypto

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Ben Smyth and Alfredo Pironti, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .