Web Hack List

Later archive addition

Crippling HTTPS with Unholy PAC

An attacker on a shared network forces a victim's browser or OS to load a hostile proxy auto-config file, whose JavaScript is handed the full URL of every request including HTTPS ones, leaking paths and the credentials or session tokens carried in them.

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.