Quick question for you guys.
Doing some experimentation with JS injection into http websites.
Obviously, most websites use https. The main workaround is to attempt to perform an sslstrip or HSTSHijack to try to downgrade the site to http. From there we can inject a hook and try from there.
However, most large sites have a strong HSTS policy that will not allow this to work.
My question is, would it be easier to just create a DNS redirect that forces users to a predefined http website. Meaning, if I go to https://google.com, it would redirect to http://palms.myspecies.info/
Obviously, this would get noticed by the target host, but that is not important as this is for testing purposes on my own machine.
[link] [comments]
from hacking: security in practice https://ift.tt/WGKUpT9
Comments
Post a Comment