[cabfpub] China MITMing icloud.com

Gervase Markham gerv at mozilla.org
Tue Oct 21 09:50:59 MST 2014


On 21/10/14 15:41, Rich Smith wrote:
> I have no way to independently verify that accusation,

Actually, you do. The cert is here:
http://www.mediafire.com/download/ampbnqncc277krv/fakeicloudcert.zip

And Qihoo 360 is here:
http://int.down.360safe.com/360browser/360browser7.5.2.110.exe

If you have a copy of Windows and the ability to set up an SSL server
and fiddle with your own DNS using a hosts file, you can test it all.

I'm missing the copy of Windows... but I'm eager to hear what everyone
else finds :-)

Gerv


More information about the Public mailing list