3 ms·
Would you mind to elaborate how A (the ability to intercept traffic) leads to B (the ability to make Let’s Encrypt issue a certificate for the (any?) host? I fa
by qpx 4y ago
Would you mind to elaborate how A (the ability to intercept traffic) leads to B (the ability to make Let’s Encrypt issue a certificate for the (any?) host? I fail to see the connection
- dolni 4y agoThere is a blog post here that describes how to exploit it: https://www.mike-gualtieri.com/posts/chaining-remote-web-vulnerabilities-to-abuse-lets-encrypt https://www.mike-gualtieri.com/posts/chaining-remote-web-vul...
- im3w1l 4y agoLet's Encrypt issues certs based on challenges. One challenge method is that they make an http request to the domain. If they get the correct response back then they will give you the cert. So what you would do is request a certificate, intercept the challenge, and answer correctly. Edit: If you did this, it would be show up in certificate transparency logs. So a very alert sysadmin could catch you in the act.
- controversial97 4y agoI point to this recent case of a BGP hijack where an attacker got a certificate issued https://nitter.lacontrevoie.fr/rmhrisk/status/1574993338084003842#m https://nitter.lacontrevoie.fr/rmhrisk/status/15749933380840...