4 ms·
If I remember correctly, most of the URL including the parameters are encrypted when you use SSL. I think the only part that isn't is the hostname
by Pwntastic 14y ago
If I remember correctly, most of the URL including the parameters are encrypted when you use SSL. I think the only part that isn't is the hostname
- gcr 14y agoAlmost right. The entire URL, including the hostname, is "encrypted," but you still have to have the IP address of the machine you're talking to, which means your machine will probably be doing (unencrypted) DNS lookups and will send encrypted packets to the target's IP address. Attackers can see the hostname of the machine you're talking to, but not because it's an "unencrypted" part of the SSL packet somehow.