有没有可能不解密流量
#209
Replies: 2 comments
-
|
不能,握手最后一步(已进入加密流量)验证全程校验码 |
Beta Was this translation helpful? Give feedback.
0 replies
-
|
不能,我试过,会直接握手失败 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
据我所知tls client hello本身没有加密(也没办法加密,因为在此之前没有时间传输公钥),然后证书应该也没有加密
能不呢只修改client hello字段和返回的正数的domain字段,避免流量解密提升性能?
但是我似乎不会用dpkt库。
还是说这个做法有问题:
我看tls重握手漏洞的解决是靠extension里面一个安全重握手标记,所以client hello包中间人无法篡改?
Beta Was this translation helpful? Give feedback.
All reactions