Web Hack List

Other nomination

Opossum Attack

Cross-protocol desynchronisation against services that offer both implicit TLS on a dedicated port and opportunistic TLS upgrade. A man-in-the-middle splices the client's TLS connection onto its own upgraded plaintext connection, leaving client and server one message apart, which gives resource confusion, session fixation and self-XSS escalation.

Record

Researcher
Robert Merget, Nurullah Erinola, Marcel Maehren, Lukas Knittel, Sven Hebrok, Marcus Brinkmann, Juraj Somorovsky and Jörg Schwenk

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Robert Merget, Nurullah Erinola, Marcel Maehren, Lukas Knittel, Sven Hebrok, Marcus Brinkmann, Juraj Somorovsky and Jörg Schwenk, first published at the original source. Preserved copies are kept so the citation survives its host.