|
|
|
|
|
by aleksejs
22 days ago
|
|
The jabber.ru post referenced here presents clear evidence (in the section titled "Network") that the malicious actor was able to reroute traffic going to the legitimate jabber.ru server. An attacker in this position does not need an RCE to get a cert, they can just get one issued the normal way, because they do effectively control the IP address that the domain is pointing to. |
|
Sprinkle some DNSSEC on the CAA record too, if you'd like.