HomeSecurityAttackers can collect your HTTPS Web traffic history!

Attackers can collect your HTTPS Web traffic history!

Alex Chapman and Paul Stone from Context, a British cybersecurity consultancy, discovered a new attack method using the WPAD protocol and PAC files to leak information about the HTTPS sites a user visits.

Their discovery is another drop in the ocean of exploits that use the widely insecure WPAD protocol.

Attackers can collect your HTTPS Web traffic history!

WPAD stands for Web Proxy Auto-Discovery and is a protocol used to broadcast proxy configurations across a network. This “broadcasting” operation done using proxy configurations is called PAC files or proxy auto-configs, which are received by browsers or other applications connecting over the Internet before being sent to their destination.

Chapman and Stone say that an attacker already on a compromised network could detect the passage of PAC files and inject malicious code. This is possible when WPAD servers use HTTP instead of HTTPS to transmit proxy configuration files.

The researchers explain that one of the available PAC functions allows an attacker to leak the full URL of an HTTPS website that they might access. Normally, when someone tries to observe HTTPS traffic, they usually only see the https://domain-name.com part of the URL.

Their attack, however, allows a malicious attacker to observe the full URL, such as https://domain-name.com/page/about/something.html.

The attack is not as devastating as BadTunnel or Hot Potato, but it is a simple way to collect Web traffic history from a target by breaking the protection provided by HTTPS traffic.

The issue affects all operating systems, as they all support WPAD and PAC files. Researchers have notified all vendors, and some of them have released patches for their products that fix the way WPAD and PAC files work. This includes Apple for iOS and OS X, and Google for Android and Chrome.

For Windows users, the two researchers recommend:

Users should disable WPAD support if it is not used on their network, usually only needed in corporate networks with strong firewalls.

Accordingly, Windows users on networks where WPAD and PAC are used should disable the default “Automatically detect settings” option in LAN Settings of Internet Properties, as shown in the image below:

 leak-HTTPS-traffic

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS