Security Analysis and Mitigation of SSL Stripping, Homograph Redirection, and Keylogging Attacks: A Case Study on Thai Web Platforms

Khathawut Chanbuala, Darunee Puangpronpitag, Egachai Puangpronpitag, Somnuk Puangpronpitag · Journal of Current Science and Technology · 2025

The cybersecurity of critical Thai digital infrastructure is a pressing concern for national security. This research, conducted in collaboration with Thailand's Department of Special Investigation (DSI), presents a comprehensive security assessment of 27 specifically selected websites across financial, commercial, and educational sectors. Our investigation focuses on three critical attacks: SSL stripping, homograph redirection attacks, and keylogger injection. The findings reveal that 96.3% (26/27) of the examined websites are vulnerable to SSL stripping attacks due to inadequate HTTP Strict Transport Security (HSTS) implementation. Notably, even the sole website with proper HSTS Preload configuration demonstrated susceptibility to homograph attacks. Furthermore, all examined websites were susceptible to keylogger injection after successful Man-in-the-Middle (MITM) attacks, even when password hashing was used. To counter these threats, we propose an enhanced security framework integrating a Time-based Salted Hash Password (TSHP) mechanism and an On-Screen Keyboard (OSK) for login interfaces. Experimental evaluation shows that TSHP improves resistance to brute-force and replay attacks by generating dynamic, time-variant hashes, while OSK input prevented 100% of JavaScript keylogger captures when used exclusively. These countermeasures offer practical, low-cost solutions to strengthen Thailand’s digital services, enabling immediate deployment without infrastructure overhaul. Our findings provide actionable recommendations for policymakers and system administrators to enhance the cybersecurity posture of Thai web platforms, with broader implications for securing digital economies globally.

Read the paper · More papers on PaperTik