Re: MITM to a cisco client

2024-05-21 Thread Daniel Lenski
On Thu, May 9, 2024 at 1:08 AM David Woodhouse wrote: > On Wed, 2024-05-08 at 17:59 -0600, Oscar Velazquez wrote: > > I have a hunch: it is to change server-cert-hash, but I do not know > > what the correct values could be or if this is a valid approach. > > Any help would be appreciated. > > > >

Re: MITM to a cisco client

2024-05-09 Thread David Woodhouse
On Wed, 2024-05-08 at 17:59 -0600, Oscar Velazquez wrote: > > > I have a hunch: it is to change server-cert-hash, but I do not know > what the correct values could be or if this is a valid approach. > Any help would be appreciated. > Probably the sha1 fingerprint of the (real) server's SSL cer

MITM to a cisco client

2024-05-08 Thread Oscar Velazquez
Hi all I am trying to pinpoint what the CSD script is doing on a cisco anyconnect windows machine, for that I put together a MITM but it is dropping the connection by the last step: POST / HTTP/1.1 Host: .com User-Agent: AnyConnect Windows 4.10.07073 Accept: */* Accept-Encoding: ident