|
|
|
|
|
by falcolas
4088 days ago
|
|
All the MITM has to do is relay the traffic to the correct secure location, passing the credentials passed via the compromised HTTP connection, and the user's entire account is compromised. Remember: HTTPS does not ensure the identity of the client. |
|
It sounds like you are talking about creating a phishing page and injecting it, hoping the user enters their credentials, and stealing them. I already said this was possible.