Web Hack List

Collected research

How I exploited ACME TLS-SNI-01 issuing Let's Encrypt SSL-certs for any domain using shared hosting

The ACME TLS-SNI-01 challenge resolved only the target domain to an IP and then looked for a generated name ending in .acme.invalid inside the certificate returned over SNI. On shared hosting such as Heroku and AWS CloudFront any tenant could claim that name and upload a matching self-signed certificate, so Let's Encrypt would issue certificates for other people's domains.

Record

Researcher
Frans Rosén
Published by
Labs Detectify
Date
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Frans Rosén, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .