4 ms·
Not what you were replying to, but SSL does provide for MITM outside of the options offered in your response. I.e. https://mitmproxy.org https://mitmproxy.org
by NotreDev 10y ago
Not what you were replying to, but SSL does provide for MITM outside of the options offered in your response. I.e. https://mitmproxy.org https://mitmproxy.org
- kecks 10y agoNo? The link you posted is indeed a MITM proxy for SSL, but it will generate certificate errors, as my grandparent said. Users will know the MITM attack is going on (unless the website doesn't use HSTS and the attacker has stolen/bought a signing key from a CA registered in your device's trust store).
- corndoge 10y agoAs a user of mitmproxy, I assure you it is not achieving MITM by exploiting any weakness of SSL. mitmproxy requires its certificate to be trusted by the target (i.e. installed in the root store) to silently intercept SSL'd traffic. Invalid certificate warnings will display otherwise. This is fully conformant to SSL's threat model.