3 ms·
Practically speaking, how would this work without also hacking the FTP server, SMTP server, or somehow hacking the original page?
by jsight 5y ago
Practically speaking, how would this work without also hacking the FTP server, SMTP server, or somehow hacking the original page?
- Lex-2008 5y agohow I understand it after reading the original article: in plaintext http world, man-in-the-middle (MitM) can redirect your browser request for www.bank.com to their own evil server which will pretend being www.bank.com. in https world this wouldn't work since evil server doesn't have a valid TLS certificate for www.bank.com and thus your browser will refuse to talk to it. However, MitM might redirect your request for www.bank.com to this bank's ftp server ftp.bank.com. If this mail server uses wildcard certificate *.bank.com - then your browser will accept it and start talking HTTP to it. this article analyzes how various (email and ftp) software reacts when sees a browser talking http to them. If an ftp server saves such request (in plaintext form) to a world-readable file - hacker can read it and we're in trouble.