SSL striping- SSL is one of the world’s most important forms of - TopicsExpress



          

SSL striping- SSL is one of the world’s most important forms of commercial encryption. The tool – called ‘SSL strip’ – is based around a man-in-the-middle attack, where the system for redirecting people from the insecure to the secure version of a web page is abused. By acting as a man-in-the-middle, the attacker can compromise any information sent between the user and the supposedly secure webpage. The author of the exploit claims to have used it to steal data from PayPal, GMail, Tickermaster, and Facebook – including sixteen credit card numbers and control of more than 100 email accounts. The problems with HTTPS- Web browsers always start off using HTTP which has zero security. No one actually manually types in HTTPS or HTTP and they generally just type gmail for example and expect the web browser to magically re-route them to a secure sign-in. Unfortunately, that relies on a mechanism that redirects the user from an insecure HTTP page to a secure HTTPS page. Yet this redirect can easily be blocked by a hostile man-in-the-middle which is exactly what SSL Strip does. This means the user never gets taken to the secure authentication page leaving their username and password in the clear for the hijacker to see and take.
Posted on: Sun, 09 Mar 2014 05:16:46 +0000

Trending Topics



Recently Viewed Topics




© 2015