HTTPS Session Hijacking Based on SSLStrip
Zhi Xue · Information Security and Communications Privacy · 2009
This article analyzes the extensively-employed HTTPS protocol and discusses the common HTTPS hijacking methods and techniques.A specific practical way — SSLStrip, which is based on man-in-the-middle technique(MITM), is proposed and analyzed in detail.The article exposes the obscure security problems concerned with https-based communication, which is generally believed to be quite safe, and provides some defending measures against SSLStrip attack.