MITM kurwisa paJABBER.RU uye XMPP.RU

MITM kurwisa paJABBER.RU uye XMPP.RU

Kubatwa kweTLS yekubatanidza nekuvharirwa kweiyo pakarepo meseji protocol XMPP (Jabber) (Man-in-the-Middle kurwisa) yakaonekwa pamaseva ejabber.ru sevhisi (aka xmpp.ru) pane vanopa vanopa Hetzner neLinode kuGermany. .

Murwisi akapa zvitupa zvitsva zveTLS zvinoverengeka achishandisa Let's Encrypt sevhisi, iyo yakashandiswa kubata yakavharidzirwa STARTTLS yekubatanidza pachiteshi 5222 uchishandisa yakajeka MiTM proxy. Kurwiswa uku kwakawanikwa nekuda kwekupera kweimwe yezvitupa zveMiTM, iyo isina kuburitswa.

Hapana zviratidzo zvekubira sevha kana spoofing kurwiswa kwakawanikwa muchikamu chetiweki; asi, zvinopesana: kudzokororwa kwetraffic kwakagadziridzwa munetiweki yeanopa.

Source: linux.org.ru

Voeg