Ukuhlasela kwe-MITM ku-JABBER.RU kanye ne-XMPP.RU

Ukuhlasela kwe-MITM ku-JABBER.RU kanye ne-XMPP.RU

Ukutholwa koxhumo lwe-TLS ngokubethela kwephrothokholi yemiyalezo esheshayo i-XMPP (Jabber) (Man-in-the-Middle attack) kutholwe eziphakelini zesevisi ye-jabber.ru (aka xmpp.ru) kubahlinzeki bokusingatha i-Hetzner ne-Linode eJalimane. .

Umhlaseli ukhiphe izitifiketi ezintsha ezimbalwa ze-TLS esebenzisa isevisi ethi Masibethele, ezisetshenziswe ukuvimba uxhumo lwe-STARTTLS olubethelwe ku-port 5222 kusetshenziswa ummeleli we-MiTM obonakalayo. Ukuhlasela kutholwe ngenxa yokuphelelwa yisikhathi kwesinye sezitifiketi ze-MiTM, esingazange siphinde sikhishwe.

Azikho izimpawu zokugetshengwa kweseva noma ukuhlaselwa kokukhwabanisa okutholwe engxenyeni yenethiwekhi; kunalokho, ngokuphambene: ukuqondisa kabusha kwethrafikhi kwalungiselelwa kunethiwekhi yomhlinzeki wokusingatha.

Source: linux.org.ru

Engeza amazwana