New issue
Advanced search Search tips

Issue 871008 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 871007
Owner: ----
Closed: Aug 6
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Bug-Security



Sign in to add a comment

--disable-features=SSLCommonNameMismatchHandling" not working / breaching our security

Reported by arjuniet...@gmail.com, Aug 4

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:61.0) Gecko/20100101 Firefox/61.0

Steps to reproduce the problem:
 Issue 870739  in chromium: CNAME redirection possible to exploit

you cant close that issue , its not that simple

What is the expected behavior?
you gave me a non working solution and closed the issue ? why ?

What went wrong?
No it didn't worked for me . I launched crome as you guided said with the switch you said ..same situation not blocking even now ..
And as you said a technically incorrect statement "IF SSL OF WWW IS PROVIDED SWITCHING BETWEEN WWW<----> NON WWW WILL BE SEEN cname redirect will not be followeed .

As per my understanding browser will first lookup dns ..got redirected by CNAME and the the tls handhake begins and SAN will be looked for domain in request and that is the CNAME redirected one

We are facing a potential secrurity issue owing to it ...plz get it resolved 

Did this work before? N/A 

Chrome version: <Copy from: 'about:version'>  Channel: n/a
OS Version: OS X 10.12
Flash Version: 

 Issue 870739  in chromium: CNAME redirection possible to exploit
you gave me a non working solution and closed the issue ? why ?
 
Mergedinto: 871007
Status: Duplicate (was: Unconfirmed)
Please do not file duplicated issues.
Project Member

Comment 2 by sheriffbot@chromium.org, Nov 13

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment