Web Hack List

Later archive addition

Virtual Host Confusion: Weaknesses and Exploits

HTTPS servers routinely serve many origins behind one certificate and one IP address. Shared TLS session caches, session tickets and SPDY connection reuse let an attacker who controls any single domain on a multi-domain certificate answer requests meant for the others, stealing cookies and sign-on tokens and bypassing certificate validation.

Record

Researcher
Antoine Delignat-Lavaud and Karthikeyan Bhargavan
Format
Whitepaper

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Antoine Delignat-Lavaud and Karthikeyan Bhargavan, first published at the original source. Preserved copies are kept so the citation survives its host.