Blog | G5 Cyber Security

BREACH, just 30s to decrypt info of SSL/TSL encrypted traffic

Breach (Browser Reconnaissance and Exfiltration via Adaptive Compression of Hypertext) is the name of an new methods to capture login tokens, session ID and other sensitive information from SSL/TSL encrypted traffic. The attack exploits the standard Deflate compression algorithm used by various websites to reduce bandwidth consumption, the hacker need to continually eavesdrop on the encrypted traffic between a victim and a web server before and the condition for exploiting success is that a victim first accesses to malicious link.”]

Source: http://securityaffairs.co/wordpress/16900/hacking/breach-just-30s-to-decrypt-from-ssltsl-encrypted-traffic.html

Exit mobile version