[11365] 2017-05-19_利用HSTS嗅探浏览器历史纪录的三个漏洞

文档创建者:s7ckTeam
浏览次数:12
最后更新:2025-01-18
2017-05-19_利用HSTS嗅探浏览器历史纪录的三个漏洞 H S T S t o c t t o u   F r e e B u f   2 0 1 7 - 0 5 - 1 9 * t o c t t o u F r e e B u f H S T S 使 H T T P S 访 H S T S H S T S W e b   |   t o c t t o u H S T S H S T S H T T P   S t r i c t   T r a n s p o r t   S e c u r i t y H T T P 2 0 1 2 1 1 I E T F R F C   6 7 9 7 H S T S H S T S H T T P S t r i c t - T r a n s p o r t - S e c u r i t y S t r i c t - T r a n s p o r t - S e c u r i t y :   m a x - a g e = 3 1 5 3 6 0 0 0         3 1 5 3 6 0 0 0 1 访 使 H T T P S 使 H S T S H T T P S   [ 1 ] H T T P S   C o o k i e   [ 2 ] H T T P 访 H S T S H S T S C h r o m e C h r o m e H S T S H S T S G o o g l e t r u s t w o r t h y i n t e r n e t . o r g   S S L   P u l s e 2 0 1 7 5 1 1 . 8 % H S T S   [ 3 ] H S T S C h r o m e E d g e I E   1 1 F i r e f o x O p e r a S a f a r i < i m g > H S T S H S T S V l a d   T s y r k l e v i c h 2 0 1 4   [ 4 ] [ 5 ] w w w . e x a m p l e . c o m H S T S 访   h t t p : / / w w w . e x a m p l e . c o m : 4 4 3 / f a v i c o n . i c o   访 访 H S T S 使 h t t p s : / / w w w . e x a m p l e . c o m : 4 4 3 / f a v i c o n . i c o f a v i c o n . i c o < i m g   s r c = " h t t p : / / w w w . e x a m p l e . c o m : 4 4 3 / f a v i c o n . i c o "   o n e r r o r = " n o t _ v i s i t e d ( ) " o n l o a d = " v i s i t e d ( ) " > o n e r r o r 访 w w w . e x a m p l e . c o m o n l o a d 访
使 H S T S H S T S 访 U R L 访 C h r o m i u m P o C   [ 4 ] h t t p 使 4 4 3 W e b S o c k e t H S T S H S T S S n i f f l y     H S T S C S P Y a n   Z h u 2 0 1 5 T o o r c o n   2 0 1 5 [ 6 ] [ 7 ] S n i f f l y F r e e b u f S n i f f l y   H S T S C S P [ 8 ] C S P h t t p s h t t p C S P C o n t e n t - S e c u r i t y - P o l i c y : i m g - s r c   h t t p : / / * h t t p h t t p s C S P h t t p s o n e r r o r h a n d l e r 使 J a v a S c r i p t h t t p h t t p s 1 0 H S T S 3 0 1 访 C h r o m e C V E - 2 0 1 6 - 1 6 1 7 C S P h t t p : / / * h t t p h t t p s h t t p h t t p s Y a n   Z h u C h r o m e P o C   [ 9 ] H S T S C S P 2 0 1 6 G o o g l e   [ 1 0 ] W e b K i t / S o u r c e / c o r e / f r a m e / c s p / C S P S o u r c e . c p p C S P S o u r c e : : s c h e m e M a t c h e s 4
C S P h t t p u r l h t t p h t t p s w s W e b S o c k e t C S P w s w s w s s U R L C S P C S P m g - s r c   h t t p : / / e x a m p l e . c o m : 8 0 C S P h t t p : / / e x a m p l e . c o m : 8 0 h t t p s : / / e x a m p l e . c o m : 8 0 U R L h t t p s 8 0 h t t p s : / / e x a m p l e . c o m h t t p s : 8 0 h t t p h t t p s C h r o m e F i r e f o x W e b K i t E d g e I E E d g e h t t p s E d g e C h r o m e P o C [ 1 1 ] M o z i l l a [ 1 2 ] W e b K i t [ 1 3 ] C V E - 2 0 1 6 - 5 1 3 7 C h r o m e C V E - 2 0 1 6 - 9 0 1 7 F i r e f o x G o o g l e 1 0 0 0 H S T S H S T S H S T S C o o k i e H S T S [ 1 4 ] [ 1 ] h t t p s : / / b l a c k h a t . c o m / p r e s e n t a t i o n s / b h - d c - 0 9 / M a r l i n s p i k e / B l a c k H a t - D C - 0 9 - M a r l i n s p i k e - D e f e a t i n g - S S L . p d f [ 2 ] h t t p s : / / w w w . u s e n i x . o r g / s y s t e m / f i l e s / c o n f e r e n c e / u s e n i x s e c u r i t y 1 5 / s e c 1 5 - p a p e r - z h e n g - u p d a t e d . p d f [ 3 ] h t t p s : / / w w w . t r u s t w o r t h y i n t e r n e t . o r g / s s l - p u l s e / [ 4 ] h t t p s : / / b u g s . c h r o m i u m . o r g / p / c h r o m i u m / i s s u e s / d e t a i l ? i d = 4 3 6 4 5 1 i o n e r r o r
[ 5 ] h t t p s : / / b u g z i l l a . m o z i l l a . o r g / s h o w _ b u g . c g i ? i d = 1 0 9 0 4 3 3 [ 6 ] h t t p s : / / w w w . y o u t u b e . c o m / w a t c h ? v = k k 2 G k Z v 6 W j s [ 7 ] h t t p s : / / z y a n . s c r i p t s . m i t . e d u / p r e s e n t a t i o n s / t o o r c o n 2 0 1 5 . p d f [ 8 ] h t t p : / / w w w . f r e e b u f . c o m / a r t i c l e s / 8 7 6 4 1 . h t m l [ 9 ] h t t p s : / / b u g s . c h r o m i u m . o r g / p / c h r o m i u m / i s s u e s / d e t a i l ? i d = 5 4 4 7 6 5 [ 1 0 ] h t t p s : / / c h r o m i u m . g o o g l e s o u r c e . c o m / c h r o m i u m / s r c . g i t / + / a b 8 3 0 e d b 2 6 a 1 f 5 6 f 6 6 0 b 0 6 4 5 9 d 7 0 e 1 d 4 8 a 7 0 7 9 7 5 [ 1 1 ] h t t p s : / / b u g s . c h r o m i u m . o r g / p / c h r o m i u m / i s s u e s / d e t a i l ? i d = 6 2 5 9 4 5 [ 1 2 ] h t t p s : / / b u g z i l l a . m o z i l l a . o r g / s h o w _ b u g . c g i ? i d = 1 2 8 5 0 0 3 [ 1 3 ] h t t p s : / / b u g s . w e b k i t . o r g / s h o w _ b u g . c g i ? i d = 1 5 9 5 2 0   [ 1 4 ] h t t p s : / / n a k e d s e c u r i t y . s o p h o s . c o m / 2 0 1 5 / 0 2 / 0 2 / a n a t o m y - o f - a - b r o w s e r - d i l e m m a - h o w - h s t s - s u p e r c o o k i e s - m a k e - y o u - c h o o s e - b e t w e e n - p r i v a c y - o r - s e c u r i t y / * t o c t t o u F r e e B u f
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则