A group of researchers from Ca' Foscari University (Italy) analyzed 90,000 hosts associated with 10,000 of the largest websites ranked by Alexa and concluded that 5.5% of them have serious security issues in the applied TLS implementations. The study examined problems related to the use of vulnerable encryption methods: 4,818 of the problematic hosts were susceptible to MITM attacks, 733 had vulnerabilities that could fully decrypt traffic, and 912 allowed for partial decryption (for example, extracting session cookies).
Serious vulnerabilities were identified on 898 websites that could lead to complete compromise, such as through script injection on pages. 660 (73.5%) of these websites used external scripts loaded from vulnerable third-party hosts, demonstrating the relevance of indirect attacks and the possibility of their cascading spread (an example is the breach of the StatCounter counter, which could have led to the compromise of over two million other sites).
10% of all login forms on the studied sites had privacy issues that could potentially lead to password theft. 412 sites had problems with intercepting session cookies. 543 sites had issues with session cookie integrity control. More than 20% of the studied cookies were susceptible to information leakage to parties controlling subdomains.
Source: opennet.ru
