| |
A security researcher conducting a routine assessment of a client's reverse gateway/load balancer infrastructure discovered a methodology to detect whether attackers had accessed personally identifiable information (PII) flowing through the encrypted traffic. By leveraging an 'X-Orig-Connection' header added by the gateway application and correlating encrypted HTTPS traffic with decrypted HTTP traffic using connection four-tuples, the researcher was able to map which TLS connections contained PII and analyze potential security breaches.
Read Full Article →
← More Tech news