Evaluating and Mitigating HTTPS Interception in Thai E-Banking Websites: Challenges and Solutions
Khathawut Chanbuala, Egachai Puangpronpitag, Darunee Puangpronpitag, Somnuk Puangpronpitag · 2024
This study examines vulnerabilities in HTTPS implementation across 12 Thai e-banking websites, focusing on HSTS misconfigurations and the potential for SSL stripping and keylogger injection attacks. The results show that all sites are susceptible to SSL stripping due to a lack of HSTS preload, allowing interception of login credentials. Furthermore, keylogger injection after MITM and SSL stripping was effective even on sites with salted-hash passwords. To mitigate these threats, the paper proposes to use an On-Screen Keyboard (OSK) combined with salted-hash passwords. Experiments with this approach demonstrate its effectiveness in preventing keystroke logging while maintaining user experience. The research underscores the need for robust technical controls and user education to enhance the security of online banking systems against evolving cyber threats.