<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>duszynski.eu</title><description>Piotr Duszyński - Personal Blog</description><link>https://duszynski.eu/</link><item><title>Disclosing Tor users&apos; real IP address through 301 HTTP Redirect Cache Poisoning</title><link>https://duszynski.eu/posts/tor-ip-disclosure-through-http-301-cache-poisoning/</link><guid isPermaLink="true">https://duszynski.eu/posts/tor-ip-disclosure-through-http-301-cache-poisoning/</guid><description>This blog post describes an example practical application of the &apos;HTTP 301 Cache Poisoning&apos; attack that can be used by a malicious Tor exit node to disclose real IP address of chosen clients.</description><pubDate>Wed, 29 May 2019 09:00:00 GMT</pubDate></item><item><title>Permanent URL Hijack Through 301 HTTP Redirect Cache Poisoning</title><link>https://duszynski.eu/posts/domain-hijack-through-http-301-cache-poisoning/</link><guid isPermaLink="true">https://duszynski.eu/posts/domain-hijack-through-http-301-cache-poisoning/</guid><description>This blog post describes an interesting technique of abusing the standard HTTP 301 responses (&quot;Permanent redirect&quot;) to poison browser cache and achieve endpoint persistence for chosen non-TLS resources.</description><pubDate>Thu, 23 May 2019 09:00:00 GMT</pubDate></item><item><title>Client Domain Hooking - Example Attack</title><link>https://duszynski.eu/posts/client-domain-hooking-in-practice/</link><guid isPermaLink="true">https://duszynski.eu/posts/client-domain-hooking-in-practice/</guid><description>In my last blog post I have released a paper that described all relevant technical aspects of the &apos;Client Domain Hooking&apos;, along with a HTTP Strict Transport Security (HSTS) survey made for the TOP 1000 Alexa websites.</description><pubDate>Mon, 20 May 2019 09:00:00 GMT</pubDate></item><item><title>Hijacking browser TLS traffic through Client Domain Hooking</title><link>https://duszynski.eu/posts/hijacking-browser-tls-traffic-through-client-domain-hooking/</link><guid isPermaLink="true">https://duszynski.eu/posts/hijacking-browser-tls-traffic-through-client-domain-hooking/</guid><description>I am releasing a paper that describes a new variation of a man-in-the-middle (MITM) technique which, under certain circumstances, allows to permanently hijack browsers encrypted HTTP communication channel flow and compromise its confidentiality and integrity.</description><pubDate>Wed, 08 May 2019 09:00:00 GMT</pubDate></item><item><title>Phishing NG. Bypassing 2FA with Modlishka.</title><link>https://duszynski.eu/posts/phishing-ng-bypassing-2fa-with-modlishka/</link><guid isPermaLink="true">https://duszynski.eu/posts/phishing-ng-bypassing-2fa-with-modlishka/</guid><description>This blog post is an introduction to the reverse proxy &quot;Modlishka&quot; tool, that I have just released.</description><pubDate>Wed, 02 Jan 2019 09:00:00 GMT</pubDate></item></channel></rss>