CONNECT
request with a plain-text message such as this:HTTP/1.0 407 Boink
Proxy-Authenticate: basic
Connection: close
Content-Type: text/html
Hi, mom!
[...additional padding follows...]
The browser would show the user a cryptic authentication prompt - but hitting ESC or pressing cancel would inevitably result in the proxy-supplied plain-text document being rendered in the same-origin context of the requested HTTPS site. There goes the transport security - so I guess that's an oops?:-)
0 nhận xét:
Đăng nhận xét