4 ms·
https://officecdn.microsoft.com https://officecdn.microsoft.com > Validity > Not Before - Fri, 18 Aug 2023 02:17:43 GMT > Not After - Thu, 27 Jun 2024 23:59:
by johnbellone 2y ago
https://officecdn.microsoft.com https://officecdn.microsoft.com
> Validity
> Not Before - Fri, 18 Aug 2023 02:17:43 GMT
> Not After - Thu, 27 Jun 2024 23:59:59 GMT
> Subject Alternative Name
> DNS Name - cdn.entity.osi.office.net
> DNS Name - cdn.entity.osi.officeppe.net
> DNS Name - cdn.uci.edog.officeapps.live.com
> DNS Name - cdn.uci.officeapps.live.com
> DNS Name - uci.cdn.office.net
> DNS Name - uci.edog.cdn.office.net
[1]: https://crt.sh/?id=12376893471 https://crt.sh/?id=12376893471
- johnbellone 2y agoIt looks like https://businessaccount.microsoft.com/ https://businessaccount.microsoft.com/ domain is also affected. [1]: https://crt.sh/?id=9852030995 https://crt.sh/?id=9852030995
- 4ggr0 2y agoi feel a bit dumb right now... always thought that using *.domain.net for home-use was cool, because that way random people don't know what kinds of subdomains i use. turns out they can find it out by just checking all the certs for my domain. well. the more you know.
- Caligatio 2y agoI have a reverse proxy that is in front of all my services (caddy) which uses a wildcard cert to avoid this very concern.
- 4ggr0 2y agoi use NPM at home. tested caddy a bit but i really liked NPMs convenience of having a Web-UI. allows me to do stuff remotely on my phone without having to dive into conf files. anyways, what i liked about caddy was how easily it handles SSL-certs, for sure makes it easier to use! :) gonna have to look into how i can give a wildcard-cert to my rev-proxy.
- kenny11 2y agoIf you use a wildcard cert, then only "*.domain.net" is recorded in the logs, not the actual hostnames you're using.
- 4ggr0 2y agoah, my mistake then. i use a wildcard dns-record but separate letsencrypt-certs for every subdomain. so to truly be stealthy i'd have to use a wildcard dns-record AND a wildcard ssl-cert. sounds like i got myself a project for this weekend, implement a wildcard cert for my rev-proxy at home :) EDIT: i guess the logs would still show the old certs, so my subdomains would still be exposed. huh. at least future subdomains would be hidden. EDIT2: are there more ways for subdomains to get exposed, other than through DNS or SSL-Certs?
- 4ggr0 2y agocan't edit my previous comment anymore. i got a wildcard-cert, implemented it on my proxy, everything works! unfortunately, to be stealthy, i almost have to switch to a different domain. then request a new public IP, and switch.
- mmh0000 2y agoYou shouldn't beat yourself up too much. TLS is HARD and poorly documented, and implementations vary significantly between applications and vendors (and are very dumbly designed). TLS is what you get when you let someone implement technology with specific domain knowledge (encryption) but no UX abilities or a comprehensive understanding of how their solution will be used. I had the same horrified realization a few years ago when someone explained Certificate Transparency[1] to me. [1] https://en.wikipedia.org/wiki/Certificate_Transparency https://en.wikipedia.org/wiki/Certificate_Transparency
- WarOnPrivacy 2y ago> https://crt.sh https://crt.sh... I like. I picked up a client with a bunch of web brands and well, you know.