Collected research
How I exploited ACME TLS-SNI-01 issuing Let's Encrypt SSL-certs for any domain using shared hosting
The ACME TLS-SNI-01 challenge resolved only the target domain to an IP and then looked for a generated name ending in .acme.invalid inside the certificate returned over SNI. On shared hosting such as Heroku and AWS CloudFront any tenant could claim that name and upload a matching self-signed certificate, so Let's Encrypt would issue certificates for other people's domains.
Record
- Researcher
- Frans Rosén
- Published by
- Labs Detectify
- Date
- Topic
- Browser
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Frans Rosén, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .