Skip to main navigation Skip to search Skip to main content

A dangerous mix: Large-scale analysis of mixed-content websites

  • KU Leuven

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

15 Scopus citations

Abstract

In this paper, we investigate the current state of practice about mixed-content websites, websites that are accessed using the HTTPS protocol, yet include some additional resources using HTTP. Through a large-scale experiment, we show that about half of the Internet’s most popular websites are currently using this practice and are thus vulnerable to a wide range of attacks, including the stealing of cookies and the injection of malicious JavaScript in the context of the vulnerable websites. Additionally, we investigate the default behavior of browsers on mobile devices and show that most of them, by default, allow the rendering of mixed content, which demonstrates that hundreds of thousands of mobile users are currently vulnerable to MITM attacks.

Original languageEnglish
Title of host publicationInformation Security - 16th International Conference, ISC 2013, Proceedings
EditorsYvo Desmedt
PublisherSpringer Verlag
Pages354-363
Number of pages10
ISBN (Print)9783319276588
DOIs
StatePublished - 2015
Event16th International Conference on Information Security, ISC 2013 - Dallas, United States
Duration: Nov 13 2013Nov 15 2013

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume7807
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference16th International Conference on Information Security, ISC 2013
Country/TerritoryUnited States
CityDallas
Period11/13/1311/15/13

Fingerprint

Dive into the research topics of 'A dangerous mix: Large-scale analysis of mixed-content websites'. Together they form a unique fingerprint.

Cite this