Quantcast
Channel: Active questions tagged https - Stack Overflow
Viewing all articles
Browse latest Browse all 1794

Is the URL authority used as a component of the encryption in HTTPS?

$
0
0

My understanding of HTTPS is that the initial server communication has the authority sent in plaintext while the remainder of the communication is encrypted, eg https://example.com/foo?bar=baz will have example.com (or at least its IP) visible as plaintext while the subpath and query will be encrypted. I'm interested in detecting a potential risk that might occur if a request is locally changed to point to a different authority whose server forwards the request as-is to a different URL. Here's an example of what I'd like to detect:

I'd like to be able to detect this being done server-side and am wondering if the encrypted block of the TLS request has any information on what authority the request was made to or if this would need to be additional information manually included in the request.


Viewing all articles
Browse latest Browse all 1794

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>