Tag: mitm
All the articles with the tag "mitm".
Permanent URL Hijack Through 301 HTTP Redirect Cache Poisoning
This blog post describes an interesting technique of abusing the standard HTTP 301 responses ("Permanent redirect") to poison browser cache and achieve endpoint persistence for chosen non-TLS resources.
Client Domain Hooking - Example Attack
In my last blog post I have released a paper that described all relevant technical aspects of the 'Client Domain Hooking', along with a HTTP Strict Transport Security (HSTS) survey made for the TOP 1000 Alexa websites.
Hijacking browser TLS traffic through Client Domain Hooking
I am releasing a paper that describes a new variation of a man-in-the-middle (MITM) technique which, under certain circumstances, allows to permanently hijack browsers encrypted HTTP communication channel flow and compromise its confidentiality and integrity.