3 ms·
Bypassing CT on Chrome in this context should be trivial: https://cs.chromium.org/chromium/src/components/certificate_transparency/chrome_require_ct_delegate.cc
by CiPHPerCoder 7y ago
Bypassing CT on Chrome in this context should be trivial: https://cs.chromium.org/chromium/src/components/certificate_transparency/chrome_require_ct_delegate.cc?rcl=ae2f49f1fce4cacac5232782d9133239ff60821a&l=182 https://cs.chromium.org/chromium/src/components/certificate_...
Set your notBefore to a date earlier than 2018-05-01 and you're golden.
- tialaramex 7y agoProbably not too much earlier https://cs.chromium.org/chromium/src/net/cert/cert_verify_proc.cc https://cs.chromium.org/chromium/src/net/cert/cert_verify_pr... Method HasTooLongValidity splits certs into four categories First, really old certs with notBefore prior to 2012-07-01. This is before the Baseline Requirements, and so Chrome gives them the benefit of the doubt and presumes they might honestly have been issued with up to 10 years to expire BUT fortunately this grandfathering of old garbage was designed to end in July 2019 so all these certs are now distrusted. Any real ones were probably long gone by then anyway. Second, those from 2012-07-01 but before 2015-04-01 get up to 60 months = 5 years. So a cert issued 2015-03-31 must expire within about ten weeks from now, a workable demo but not a long-lived attack tool. Third, from 2015-04-01 but before 2018-03-01 it was 39 months. So any cert from 2015-04-01 is long expired, but one claiming it was issued 2018-02-28 expires in May 2021, that's a nice long time to exploit this bug. Finally from 2018-03-01 it was shortened to 825 days. A cert from 2018-04-30 would thus expire in August 2020. So the sweet spot is claiming issuance in February 2018. Edited: I can't count to four apparently.