4 ms·
I would call this a "self-induced man in the middle attack". You're telling your computer that cloudflarechallenge.com is his server.
by pushrax 12y ago
I would call this a "self-induced man in the middle attack". You're telling your computer that cloudflarechallenge.com is his server.
- jsmeaton 12y agoThe point is you can connect to it with HTTPS and your browser doesn't throw up big flashy warnings. It's basically proof that he has got the private key, since he can impersonate cloudfarechallenge.com with regards to SSL.
- Theriac25 12y agoHe doesn't have to have the private key, only a private key that was signed by any of the hundreds (counting intermediate CAs, thousands?) CAs trusted by his browser.
- paulbaumgart 12y agoCAs will verify that you at least have control over hostmaster@ or an email listed in the WHOIS info for the domain before issuing certs.
- gojomo 12y agoHe has to have the private key that matches the certificate he's presenting. He's presenting the CloudFlare-obtained cert (which the site offers up on request), so the lack of a warning means he's got that private key. Getting another CA-signed certificate, naming 'www.cloudflarechallenge.com' and matching another private key, would itself be an impressive compromise, though not the challenge CloudFlare made or what he's demonstrating.
- cpach 12y agoSee here how to verify that Indutny indeed snatched the private key from Cloudflare’s server: http://dankaminsky.com/2014/04/12/bloody-cert-certified/ http://dankaminsky.com/2014/04/12/bloody-cert-certified/
- pushrax 12y agoYes, of course. That's why it's a successful "man in the middle attack" of sorts. If the cert wasn't trusted then it would mean nothing.