logo

Excellent paper from MSFT Research on inline proxies vs. SSL

ID: 6080c67f-1b42-5291-84eb-970d33182d72

STIX ID: report--6080c67f-1b42-5291-84eb-970d33182d72

Feed Name: SensePost Blog

Threat Score
35/100

Date Published: 2009-06-07

Date Updated: 2026-04-29

...
...

This short write-up reviews the Microsoft Research paper 'Pretty-Bad-Proxy', which demonstrates techniques for malicious inline proxies to inject a 502 response that causes browsers to execute attacker-controlled JavaScript in the security context of an HTTPS site (enabling credential/session theft). The authors disclosed the issue to vendors and it was subsequently remediated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.