|
我公司一个客户是美国的,他们用Hurricane Lab 检测出我们的VPN
单松跃
2015-5-6 16:47
3026
我公司一个客户是美国的,他们用Hurricane Lab 检测出我们的VPN有以下问题,麻烦某公司专家看看需要打什么补丁上去????
Affected Resources:
svc:61.155.112.67:tcp:443
Issue:T
he remote web server allows injection of plaintext while data is being compressed priod to encryption. By comparing the size changes between the original and altered payload ,an attacker can determine the overlap between the two payloads and decipher the content of the sensitive data. Most modern browsers do not allow the compression of encrypted traffic.
Implication:
If the attacker intercepts a connection to this service,it is possible for them
to inject data before an encrypted channel has been established, allowing them to extract sensitive content. |
该疑问已被 解决,获得了 20 S豆
回帖即可获得
2S豆
,被楼主采纳即奖励 20S豆+10分钟内回帖奖励 10S豆
[已过期]
, 了解更多S豆奖励信息
完善手机号和公司名称,让服务更省心更便捷!立即完善
|