Web Hack List

Other nomination

Same Origin Spoofing to Attack Client Certificate Sessions

Shows SSL client certificates do not stop a server-impersonating attacker. Mallory completes a handshake without validating Alice's certificate, returns a page holding attacker script plus an iframe to the real site, then closes the connection so the iframe renegotiates legitimately. Same-origin access from the injected script then reads the mutually authenticated frame.

Record

Researcher
Tom Ritter
Published by
isecpartners.com

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Tom Ritter, first published at the original source. Preserved copies are kept so the citation survives its host.