2 ms·
But not everyone uses wildcard certs so enumeration is a problem. Also lots of people use certs with internal hostnames on public servers (they shouldn’t but it
by funnybeam 6y ago
But not everyone uses wildcard certs so enumeration is a problem. Also lots of people use certs with internal hostnames on public servers (they shouldn’t but it does make some things easier and not everyone is aware of the security issues). When CT first came out I remember running searches for some of our client’s domains and being easily able to identify Exchange servers, RDP servers, etc along with the corresponding internal hostnames which makes it easy to identify potential targets for attack.
Obscurity does have a role to play in security - leaving your front door unlocked is unlikely to be a problem but if you publish that information in a publicly searchable database then you are making yourself a target