CRIME attack (CVE-2012-4929) 

In a Compression Ratio Info-leak Made Easy (CRIME) attack, the attacker exploits a vulnerability in TLS compression. Following diagram demonstrates CRIME attack: 

This compression is basically and, optionally, used to reduce the bandwidth using the DEFLATE algorithm, for example. To defend against this attack, make sure that your browser is up to date.

Get Advanced Infrastructure Penetration Testing now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.