3 ms·
chisel is a similar tool in this space https://github.com/jpillora/chisel https://github.com/jpillora/chisel I don’t get why headers and requests need to be sp
by tomsonj 2y ago
chisel is a similar tool in this space https://github.com/jpillora/chisel https://github.com/jpillora/chisel
I don’t get why headers and requests need to be spoofed if all traffic is over https?
- Titan2189 2y ago> I don’t get why headers and requests need to be spoofed if all traffic is over https? https://en.wikipedia.org/wiki/Deep_packet_inspection https://en.wikipedia.org/wiki/Deep_packet_inspection
- mhio 2y agoThe headers are seen by the monster-in-the-middle CDN. It's obfuscation at best. I'm not sure the encrypted traffic will look particularly php-ish for example. Compressed formats might look vaguely passable. I can't see any stenography code or libraries in the repo.
- tomsonj 2y agoyeah if the CDN is not trusted this tool won’t help but then little would
- coretx 2y agoBecause SNI. Also, State (sponsored) Actors are certificate authorities. HTTPS is the biggest scam in internet history. https://en.wikipedia.org/wiki/Server_Name_Indication https://en.wikipedia.org/wiki/Server_Name_Indication
- astrange 2y agoThis certainly was an issue but it's solved by ECH/DoH. As long as they aren't blocked on your network anyway. > Also, State (sponsored) Actors are certificate authorities. To generate a fake certificate as a CA you have to either put it in the Certificate Transparency log, in which case everyone will notice, or don't, in which case browsers will notice (they know what top sites' certificates are supposed to look like) and your CA will get shut down.
- hamilyon2 2y agoSomeone should really test it, real red team black hat style and then fully publish the results. Try to mitm https with real unlogged certs and see what happens. Preregister the whole fully detailed procedure on blockchain. And report to public results fully, with proofs of being caught.
- account42 2y agoSNI doesn't expose headers and request paths.
- duskwuff 2y ago> I don’t get why headers and requests need to be spoofed if all traffic is over https? Because the traffic is to a CDN endpoint (like Cloudflare) which expects it to be a HTTP message.
- tomsonj 2y agoit can still be an https message, who cares what the path, query string, or headers look like? that is all encrypted