4 ms·
I don't even know what could be "validated" that an attacker couldn't fake. The only real validation that can be done is if the certificate is valid for the dom
by mdeeks 9y ago
I don't even know what could be "validated" that an attacker couldn't fake. The only real validation that can be done is if the certificate is valid for the domain.
- jlgaddis 9y agoA valid certificate with a hostname matching the server's? In this case, it's POST'ing the credentials before the certificate is validated.
- dogma1138 9y agoAgain this isn't the case, I've tested it out myself and I get a prompt to confirm the SSL certificate when an invalid certificate is used. This is the step that the author gracefully has omitted: https://imgur.com/a/OXIal https://imgur.com/a/OXIal, and no nothing is sent until you approve the certificate. I can't be bothered to set up an actual exchange server to check what happens if you change the certificate midway, however having to approve a certificate change before when the certificates were rotated at my previous employer at least twice on an iPhone (and much older than the current iOS) it would bet that nothing is being sent.
- dogma1138 9y agoRead it again, the SSL is validated normally. What isn't "validated" is the fact that there is a real exchange server beyond the HTTP/HTTPS endpoint. You can do a layer 7 validation and validate that there is an actual exchange server beyond the HTTP endpoint but as I stated it's utterly useless since if you can MitM the SSL connection answer "yes I'm a real exchange server" won't be a technical problem at that point. The author basically sees something that isn't there, the mail app tries to connect to an exchange server, it does so over SSL, it does validates the SSL certificate or prompts the user to approve it if the chain cannot be validates, it does however sends your credentials in the request to the server like it should.