PHWinfo banniere

Titres
PORTAIL ANNUAIRE ARTICLES COMPARATEUR HÉBERGEURS DEVIS FORUMS RÉDUCTEUR D'URL
Précédent   PHWinfo > Forums Hébergement > Forum Noms de domaine > comp.protocols.tcp-ip > Web Proxy Client with HTTPS
S'inscrire FAQ Membres Recherche Messages du jour Marquer les forums comme lus
comp.protocols.tcp-ip TCP and IP network protocols.

Web Proxy Client with HTTPS

Réponse
 
LinkBack Outils de la discussion
Vieux 17/09/2007, 18h48   #1
Eagle
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Web Proxy Client with HTTPS

Hello,

I've been asked if my application can be used over a
Proxy Client. A quick study seems to imply that this
could allow a man-in-the-middle attack by the Proxy
Service. Is that correct? I presume the customer
wants to legitamately monitor activity. I use a
secure web (HTTPS) connection to talk with my
secure servers.

David
  Réponse avec citation
Vieux 19/09/2007, 03h32   #2
slebetman@yahoo.com
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Web Proxy Client with HTTPS

On Sep 18, 1:48 am, "Eagle" <FlyLikeAnEa...@United.Com> wrote:
> Hello,
>
> I've been asked if my application can be used over a
> Proxy Client. A quick study seems to imply that this
> could allow a man-in-the-middle attack by the Proxy
> Service. Is that correct? I presume the customer
> wants to legitamately monitor activity. I use a
> secure web (HTTPS) connection to talk with my
> secure servers.
>


HTTPS should prevent man in the middle attack. Unlike HTTP, HTTPS
connections are handled via the CONNECT method which simply relays
binary data between the client and server. In theory the proxy server
can fake the CONNECT and do a man in the middle attack (indeed there
are products out there that have this as a "feature") but doing so
will result in a certificate error. Just tell your customer to never
ignore certificate errors. Another safety precaution is to tell your
customer to accept your certificate *permanently* the first time he
connects. That way the client software can detect certificate changes
better -- if a window even pops up then he should be suspicious even
if its not an error window.

  Réponse avec citation
Vieux 19/09/2007, 04h24   #3
Eagle
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Web Proxy Client with HTTPS

Thank you. I was wondering how a proxy could exist in-stream
and not behave as a man-in-the-middle. I believe that fits
well -- we keep secure conversations and they get to insure
we only contact the stated secure web sites. BTW, my client
application won't talk unless the certificates are recognized.

David
  Réponse avec citation
Réponse


Outils de la discussion

Règles de messages
Vous ne pouvez pas créer de nouvelles discussions
Vous ne pouvez pas envoyer des réponses
Vous ne pouvez pas envoyer des pièces jointes
Vous ne pouvez pas modifier vos messages

Les balises BB sont activées : oui
Les smileys sont activés : oui
La balise [IMG] est activée : oui
Le code HTML peut être employé : non
Trackbacks are oui
Pingbacks are oui
Refbacks are oui


Fuseau horaire GMT +1. Il est actuellement 09h04.


Édité par : vBulletin® version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC5 Tous droits réservés.
Version française #16 par l'association vBulletin francophone
PHWinfo est un site Éducation Sans Frontières ©2000-2008
Ad Management by RedTyger
©Tous droits réservés par les parties respectives
Page generated in 0,11432 seconds with 11 queries