Other nomination
Same Origin Spoofing to Attack Client Certificate Sessions
Shows SSL client certificates do not stop a server-impersonating attacker. Mallory completes a handshake without validating Alice's certificate, returns a page holding attacker script plus an iframe to the real site, then closes the connection so the iframe renegotiates legitimately. Same-origin access from the injected script then reads the mutually authenticated frame.
Record
- Researcher
- Tom Ritter
- Published by
- isecpartners.com
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Tom Ritter, first published at the original source. Preserved copies are kept so the citation survives its host.