Abstract:
This paper discusses the HTTPS protocol communication process is analyzed in detail based on forged certificates and man in the middle session hijacking the basic principles and methods, it is pointed out that conventional hijacking method through the backend to manipulate the original data flow and defects, and put forward a front-end scripting XSS based on injection of more efficient, more perfect HTTPS session hijacking method, has realized the form submission, dynamic elements, the window script, the hijacking of the page frame. At last, this paper describes the principle and process of the Web front end hijacking, build a prototype system to verify the security risk, and further analyze the HTTPS communications security risks, and to provide the feasible preventive measures.
Tag:
点此返回栏目查看更多>>>参考论文