|
|
|
|
|
by leepowers
4255 days ago
|
|
If an attacker controls the access point he could do the following: * Redirect all HTTPS traffic to an HTTP spoof site. Many users probably wouldn't notice. * If the attacker has access to a short, 2-3 character domain, they could redirect to a wildcard HTTPS connection like, https://facebook.aa.com/ - again, many users wouldn't notice. They'd see "facebook" and the lock icon and assume they're ok. * In either case the attacker could simply proxy all HTTP requests from victim to Facebook (or any other site). So the user's browsing experience remains the same but all passwords, cookies and personal info are logged. Scary stuff! |
|