Tag: hsts
All the articles with the tag "hsts".
Client Domain Hooking - Example Attack
In my last blog post I have released a paper that described all relevant technical aspects of the 'Client Domain Hooking', along with a HTTP Strict Transport Security (HSTS) survey made for the TOP 1000 Alexa websites.
Hijacking browser TLS traffic through Client Domain Hooking
I am releasing a paper that describes a new variation of a man-in-the-middle (MITM) technique which, under certain circumstances, allows to permanently hijack browsers encrypted HTTP communication channel flow and compromise its confidentiality and integrity.