GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Wednesday, 25-Oct-2023 04:02:16 JSTWolf480plWolf480pl
    in reply to
    • feld
    • jabberati

    @jabberati @feld
    they attacker could try send valid XMPP stanzas unencrypted, together with the starttls and a buggy server may interpret them as part of the encrypted and authenticated connection after starttls.

    If a server has a bug like that, an attacker in a MITM position can inject stanzas into client's session without actually MITMing the TLS.

    this blog has an example for SMTP:

    https://blog.apnic.net/2021/11/18/vulnerabilities-show-why-starttls-should-be-avoided-if-possible/
    (haven't read the whole blog post, only the example SMTP exchange)

    In conversationWednesday, 25-Oct-2023 04:02:16 JST from mstdn.iopermalink
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.