SSL establishes a private authenticated link to the server and then sends an HTTP request at that link. The link-tracking attacker actually speaks by simply observing the connection used by http. In SSL, it has some unencrypted headers that it uses to establish this connection, although they should not be confused with headers that are part of the http protocol.
source share