Episode #823 Quiz
TLS Confusion Attacks
Date: 2021-06-15 | Length: 2 hrs | Episode page at twit.tv
About this episode
ALPACA describes TLS application-layer confusion: because TLS authenticates only the TCP session, not the intended service, attackers can MITM-redirect HTTPS to SMTP, IMAP, POP3, or FTP endpoints sharing certificates. Research found 1.4 million vulnerable web servers, enabling cookie theft or JavaScript injection. ALPN is the main mitigation.
Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.