|
|
|
|
|
by adamconroy
2818 days ago
|
|
I don't see how this 'man' in the middle could actually intercept passwords, except for http, but who runs auth over http anyway. For https, the 'man' would have to substitute its own certificate and then the browser / client software wouldn't trust the cert/domain combination without the end user being extremely stupid (and knowledgeable enough to achieve the stupidity). |
|
The malware doesn't have to add a new root certificate, either, though that's completely possible. The Zeus trojan [3] does "man-in-the-browser" to intercept banking information, for example.
[1] https://github.com/secretsquirrel/BDFProxy
[2] https://www.pcworld.com/article/2839152/tor-project-flags-ru...
[3] https://en.wikipedia.org/wiki/Zeus_(malware)