Full Disclosure mailing list archives

Re: How to prevent HTTPS MitM


From: Jann Horn <jannhorn () googlemail com>
Date: Thu, 17 Jan 2013 22:14:32 +0100

On Thu, Jan 17, 2013 at 09:56:53PM +0100, Luigi Rosa wrote:
If this message is offtopic, please excuse me.

I was reading about Nokia HTTPS MitM. Many corporate firewall can MitM HTTPS
for content inspection and many governments do this for their reasons.

I was thinking: could it be possible to create a fake HTTPS stream to DoS the
MitM attempt?

You could probably just capture the first packet of the SSL stream that your browser
sends for a valid request and then replay it... that's probably the easiest way.

Attachment: signature.asc
Description: Digital signature

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: