8
submitted 6 days ago by [email protected] to c/[email protected]
you are viewing a single comment's thread
view the rest of the comments
[-] [email protected] 5 points 6 days ago

Not going to downplay the vulnerability, but the key requirement for this attack is that both attacker and the victim domain must both be present in the SSL certificate's SAN entries. This is something that can happen, e.g. with some web hosters, but is probably pretty rare.

this post was submitted on 27 May 2025
8 points (100.0% liked)

Cybersecurity

7274 readers
153 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 2 years ago
MODERATORS