LWN.net Logo

Blaze: The Spy in the Middle

Blaze: The Spy in the Middle

Posted Mar 24, 2010 20:51 UTC (Wed) by Gollum (subscriber, #25237)
Parent article: Blaze: The Spy in the Middle

If anyone wants to play with this capability, OWASP Proxy allows you to simulate it quite easily.

Basically, it uses a CA cert to sign site-specific certs on demand (as encountered). Typically, that CA cert will be self-generated, and self-signed, and would have to be manually imported into the targeted browsers. However, in the scenario in the story, that CA cert would actually already be trusted by the browser, and no manual import step would be required.

See http://www.owasp.org/index.php/Category:OWASP_Proxy


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds