Researchers use bypass attacks to steal encrypted information

Source: Internet
Author: User

Researchers use bypass attacks to steal encrypted information

The attacks against SSL/TLS discovered in the past few years usually require attackers to be in the middle, that is, requiring them to sniff or manipulate traffic. Two security researchers reported a new method of combined bypass attacks at the Black Hat Security Conference, without man-in-the-middle sniffing traffic. This attack technology is called HEIST: HTTP Encrypted Information can be Stolen through TCP-windows (PDF ), the information contained in the encrypted response is inferred based on the vulnerability of the Cross-response packet size transmitted over the TCP layer and the lack of the plaintext information length hiding capability in SSL/TLS. Researchers can use this method to decrypt sensitive information such as the email address and social security account contained in the encrypted response. Two researchers disclosed their findings to Google and Microsoft in advance before publishing a report. They attacked by displaying malicious third-party ads on their websites. Currently, the only method to mitigate attacks is to disable third-party cookies, whereas most browsers currently accept third-party cookies by default, the researchers said.

This article permanently updates the link address:

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.