Email or username:

Password:

Forgot your password?
1,698 posts total
27329ed9-2211-a1ba-9371-e2641bf0dcb6
SIGIOT

Signal that you receive if an Internet Of Things device was found in your local network. You must find it and replace it with a dumb, not connected to the Wi-Fi and not having a complex firmware, device.
27329ed9-2211-a1ba-9371-e2641bf0dcb6
https://notes.valdikss.org.ru/jabber.ru-mitm/

TL;DR: we have discovered XMPP (Jabber) instant messaging protocol encrypted TLS connection wiretapping (Man-in-the-Middle attack) of jabber.ru (aka xmpp.ru) service’s servers on Hetzner and Linode hosting providers in Germany.
The attacker has issued several new TLS certificates using Let’s Encrypt service which were used to hijack encrypted STARTTLS connections on port 5222 using transparent MiTM proxy. The attack was discovered due to expiration of one of the MiTM certificates, which haven’t been reissued.
There are no indications of the server breach or spoofing attacks on the network segment, quite the contrary: the traffic redirection has been configured on the hosting provider network.
The wiretapping may have lasted for up to 6 months overall (90 days confirmed). We believe this is lawful interception Hetzner and Linode were forced to setup.
https://notes.valdikss.org.ru/jabber.ru-mitm/

TL;DR: we have discovered XMPP (Jabber) instant messaging protocol encrypted TLS connection wiretapping (Man-in-the-Middle attack) of jabber.ru (aka xmpp.ru
27329ed9-2211-a1ba-9371-e2641bf0dcb6
Ну да, примерно так я Кубань и представляю.
Go Up