Blog | G5 Cyber Security

CRIME – New SSL/TLS attack for Hijacking HTTPS Sessions

The new attack is based on a weak spot in a feature in all versions of TLS 1.0. The attack code needs to be loaded inside the victim’s browser. It can be done either by tricking the victim into visiting a rogue website or by injecting the attack code into an existing HTTP connection. CRIME was tested successfully with Mozilla Firefox and Google Chrome. It doesn’t require browser plug-ins to work; JavaScript was used to make it faster, but it could also be implemented without it.

Source: https://thehackernews.com/2012/09/crime-new-ssltls-attack-for-hijacking.html

Exit mobile version