Web Hack List

Collected research

Virtual Host Confusion: Weaknesses and Exploits

HTTPS servers routinely serve many origins behind one certificate and one IP address. Shared TLS session caches, session tickets and SPDY connection reuse let an attacker who controls any single domain on a multi-domain certificate answer requests meant for the others, stealing cookies and sign-on tokens and bypassing certificate validation.

Record

Researcher
Antoine Delignat-Lavaud and Karthikeyan Bhargavan
Published by
blackhat.com
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Antoine Delignat-Lavaud and Karthikeyan Bhargavan, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .