logo

SSL: The Sites Which Don't Want To Protect Their Users

ID: a9e27d0e-adf0-5037-9eb7-5ccbb61e87d2

STIX ID: report--a9e27d0e-adf0-5037-9eb7-5ccbb61e87d2

Feed Name: Zscaler Security Research Blog

Threat Score
50/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This blog post demonstrates that several popular websites (Amazon, Basecamp, Facebook) fail to properly enforce HTTPS, exposing users to session side‑jacking via issues like HTTPS-to-HTTP redirects, mismatched certificates, and mixed insecure requests; the author references the Firesheep tool to illustrate how captured cookies can be used to hijack sessions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.