New TLS Attack Lets Attackers Launch Cross-Protocol Attacks Against Secure Sites
New TLS Attack Lets Attackers Launch Cross-Protocol Attacks Against Secure Sites Researchers have disclosed a new type of attack that exploits misconfigurations in transport layer security (TLS) servers to redirect HTTPS traffic from a victims web browser to a different TLS service endpoint located on another IP address to steal sensitive information. The attacks have been dubbed ALPACA, short for "Application Layer Protocol Confusion - Analyzing and mitigating Cracks in tls Authentication," by...
United States University Of Applied Sciences Ruhr University Bochum Paderborn University Layer Protocol Confusion Applied Sciences
Source: thehackernews.com