Chapter Five - Web App Sec
Chapter Five - Web App Sec
PERL
Client PYTHON
Response Custom
Code
Requests cookie
Brow
ser Server
Returns data
PKBob SKBob
• Bob generates (SKBob , PKBob )
• Alice: using PKBob encrypts messages and only Bob can
decrypt
SiTE - AAiT - AAU 57
SSL/TLS overview…
browse serve
r client- r
hello cert
server-hello + server-cert SK
(PK)
key exchange (several options): EC-DHE
RSA server-key-
exchange
client-key-
exchange
k Finishe k
d
HTTP data encrypted
❖Intended goal:
• Provide user with identity of page origin
• Indicate to user that page contents were not viewed or
modified by a network attacker