5 ms·
This wouldn't really be possible with a modern browser, luckily, since they don't let users bypass the warning for sites with HSTS.
by endless1234 8y ago
This wouldn't really be possible with a modern browser, luckily, since they don't let users bypass the warning for sites with HSTS.
- lucb1e 8y agoYeah for Gmail or some other big website. The real targets are usually the smaller corporate sites which are not in the preload list, but you wouldn't use those to demo with...
- endless1234 8y agoWell as long as the site has HSTS and the user had visited it at least once before the MiTM attempt.. But yeah a gazillion corporate sites won't have HSTS configured
- e12e 8y agoIn this case, the user runs the browser from a guest account - that the "attacker" controls. It would be prudent to start with a clean profile - so no "earlier" visits.
- chainsaw10 8y agoLocally-installed root CAs are allowed by HSTS, so if you added the HTTPS proxy to the root store, this would work without warning, unless you manually checked the certificate. Of course, this only works on machines you're the admin of, which is why it's allowed.