HTTPS: A phishing attack in a network

Diana Gabriela Noemí Benítez-Mejía, Alejandro Zacatenco-Santos, Linda Karina Toscano-Medina, Gabriel Sánchez-Pérez

Producción científica: Capítulo del libro/informe/acta de congresoContribución a la conferenciarevisión exhaustiva

2 Citas (Scopus)

Resumen

In this paper, we discuss the possibility of finding phishing attacks even in cases where the victim sees in their web browser, the same URL as the legitimate website with the padlock and the HTTPS certificate. This attack is not easy to detect due to the fact that it complies with security measures as a legitimate HTTPS connection. We perform the attack with a web server and a fake certificate authority. The web server hosts the phishing website, whereas the fake certificate authority, issues the certificates for the website. The success of this attack occurs when the victim or the attacker exports the certificates into the web browser. With this paper we prove that some web browsers are vulnerable to this attack, despite their having their own certificate authorities list.

Idioma originalInglés
Título de la publicación alojadaICICM 2017 - Proceedings of the 7th International Conference on Information Communication and Management
EditorialAssociation for Computing Machinery
Páginas24-27
Número de páginas4
ISBN (versión digital)9781450352796
DOI
EstadoPublicada - 28 ago. 2017
Evento7th International Conference on Information Communication and Management, ICICM 2017 - Moscow, Federación de Rusia
Duración: 28 ago. 201730 ago. 2017

Serie de la publicación

NombreACM International Conference Proceeding Series
VolumenPart F131202

Conferencia

Conferencia7th International Conference on Information Communication and Management, ICICM 2017
País/TerritorioFederación de Rusia
CiudadMoscow
Período28/08/1730/08/17

Huella

Profundice en los temas de investigación de 'HTTPS: A phishing attack in a network'. En conjunto forman una huella única.

Citar esto