Full Disclosure mailing list archives
Re: How to prevent HTTPS MitM
From: Jann Horn <jannhorn () googlemail com>
Date: Thu, 17 Jan 2013 22:14:32 +0100
On Thu, Jan 17, 2013 at 09:56:53PM +0100, Luigi Rosa wrote:
If this message is offtopic, please excuse me. I was reading about Nokia HTTPS MitM. Many corporate firewall can MitM HTTPS for content inspection and many governments do this for their reasons. I was thinking: could it be possible to create a fake HTTPS stream to DoS the MitM attempt?
You could probably just capture the first packet of the SSL stream that your browser sends for a valid request and then replay it... that's probably the easiest way.
Attachment:
signature.asc
Description: Digital signature
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- How to prevent HTTPS MitM Luigi Rosa (Jan 17)
- Re: How to prevent HTTPS MitM Jeffrey Walton (Jan 17)
- Re: How to prevent HTTPS MitM Jann Horn (Jan 18)
- Re: How to prevent HTTPS MitM gremlin (Jan 18)