Compression Ratio Info-leak Made Easy (CRIME)

Attackers aim to capture the cookies over connections that use HTTPS protocol and Speedy (SPDY) protocol, which utilize TLS data compression and compare the size of the cipher text sent by the browser during data exchange to determine either the session or encrypted communication to hijack the session of a victim, typically performing a session replay attack.

Get Mastering Kali Linux for Advanced Penetration Testing - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.