Spyke

Syndicated from the fediverse. Read and engage on the original instance.

View original on infosec.pub
crypto·Cryptography @ Infosec.pubbyNatanael

Opossum Attack - Application Layer Desynchronization using Opportunistic TLS

Opossum is a cross-protocol application layer desynchronization attack that affects TLS-based application protocols that rely on both opportunistic and implicit TLS. Among the affected protocols are HTTP, FTP, POP3, SMTP, LMTP and NNTP.

Note: The vast majority of websites are not vulnerable as HTTP TLS upgrade (RFC 2817) was never widely adopted and no browsers support it.

https://opossum-attack.com/Open linkView original on infosec.pub
3

No replies yet

No comments on the original post yet.
Opossum Attack - Application Layer Desynchronization using Opportunistic TLS | Spyke