Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
netresec
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
netresec
5y ago
We deleted this tweet earlier today. Thanks to everyone who fact checked our statement and reached out to notify us about the mistake! A correction has been posted here: https://twitter.com/netresec/status/14402989
2.
▲
by
netresec
5y ago
Yes. Sorry for the confusion. The original tweet has now been removed and a correction has been posted instead.
3.
▲
by
netresec
5y ago
We first tried to post replies with corrected information, but it didn't seem to help. The tweet has now been deleted and a correction tweet has been posted instead.
4.
▲
by
netresec
5y ago
The PCAP in the referenced tweet was created using PolarProxy, which decrypts and re-encrypts TLS traffic while saving the decrypted traffic to a PCAP file.
5.
▲
by
netresec
5y ago
MitM'ing the traffic using a trusted root CA allows TLS traffic to be decrypted, even if perfect forward secrecy is used. That's what we did to produce the decrypted PCAP shown in the Wireshark screenshot.
6.
▲
by
netresec
5y ago
You are completely right. The traffic was sent as TLS encrypted HTTP/2 traffic to Microsoft. We decrypted it using PolarProxy in order to see what was transmitted. The screenshot in the tweet shows the decrypted PCAP generated by Polar
7.
▲
by
netresec
5y ago
You are correct. This traffic was not generated by typing text into the "run box", it was generated by typing text into the "start menu box". We are very sorry for the confusion this has caused. The wireshark screenshot
8.
▲
Findject.py – a new tool to detect man-on-the-side attacks like QUANTUM INSERT
(netresec.com)
2 points
by
netresec
10y ago
|
0 comments
9.
▲
Covert Man-On-the-Side Attacks (a.k.a. QUANTUM INSERT)
(netresec.com)
3 points
by
netresec
11y ago
|
0 comments
10.
▲
Rinse-Repeat Intrusion Detection – a blacklist/signature free approach
(netresec.com)
2 points
by
netresec
11y ago
|
0 comments
11.
▲
China's Man-On-the-Side Attack on GitHub
(netresec.com)
692 points
by
netresec
12y ago
|
309 comments
12.
▲
Verifying Chinese MITM of Yahoo #GFW #UmbrellaRevolution
(netresec.com)
2 points
by
netresec
12y ago
|
0 comments
13.
▲
by
netresec
12y ago
The purpose of the "Great FIrewall of China" is to censor the Internet, i.e. the intention of this MITM doesn't seem to be to covertly spy on the University user's searches. A self signed X.509 cert is enough in order to
14.
▲
by
netresec
14y ago
New findings regarding the Chinese MITM of GitHub.com can be found here: http://netresec.com/?b=1328C6B Turns out the guy who uploaded the packet capture file was @chenshaoju