4 ms·
Unfortunately much like every nice thing on the internet, once it is being abused, it gets axed... Domain fronting (having Host header differ to SNI in TLS) is
by ebfe1 4y ago
Unfortunately much like every nice thing on the internet, once it is being abused, it gets axed... Domain fronting (having Host header differ to SNI in TLS) is a powerful way a malware author could send payload into organisations.. imagine seeing seemingly legitimate traffic to azure.com but end up with malwaredomain.com/lulz.exe... Unless organisations are peeking into TLS, check Host header, response with MZ file header...There is nothing they can do to stop this.
- SturgeonsLaw 4y agoSecurity teams should be doing DPI, using a corporate controlled CA to decrypt the traffic and then feed it into a SIEM which should start screaming bloody murder when it detects a mismatch between SNI and the requested host
- ebfe1 4y agobig corporation with everyone working in a building, 100% achievable but with everyone working from home these days, it's a big challenge to have all users' internet traffic through a single gateway in some sort of VPN is not scalable. Most corp has to support split tunnel to make it work-able... Lots of IoC base on DNS as well so that is out of the windows since the malicious traffic is inside TLS...:-/
- cryptonym 4y agoIt's more about mismatch between host and SAN. Mismatch between SNI and host is quite common with h2 connection coalescing.