3 ms·
I don’t think this is ultimately the vulnerability, but even without SNI, it’s arbitrary to dynamically link to a file, script, png, etc... hosted on a sub doma
by atxlurker 7y ago
I don’t think this is ultimately the vulnerability, but even without SNI, it’s arbitrary to dynamically link to a file, script, png, etc... hosted on a sub domain with the bad cert.
- cjbprime 7y agoOh yeah! So it's like: * client asks for cert * you give it to them * client tells you the page they want and their useragent * if you think they're vulnerable based on what you've learned about them, you add <img src="https://vulnerable.subdomain/"> https://vulnerable.subdomain/"> to the response. Neat suggestion. Thanks! Agree we've moved well outside of tomorrow's likely actual vuln.