Afterthought:

  1. This is NOT a secure solution, although Mallory is not currently equipped to handle response from Charlie, it certainly can be adapted to do so (eg. filter incoming traffic, script injection).

  2. I am almost certain Bob cannot trick Charlie into establishing a HTTPS connection with Alice, but I could be wrong, as one of the pre-condition for securing connection is for Alice to NOT give the key to a third-party, which we will in this case.

  3. As a temp solution this should work seamlessly with West Chamber (which filters fake responses so Alice can maintain the connection), the difference between server Bob and Web Proxy/VPN/SSH tunnel/whatnot is that data from Charlie goes directly to Alice, so Bob’s bandwidth/CPU cost can be kept to minimal.

  4. As mentioned in the diagram, each Bob should only handle a limited amount of users, otherwise it will be flagged as DoS. On the plus side, since no service other than authentication or request forging is offered by Bob, it has limited exposure, making it harder to identify.

  5. If you think about it, this is effectively “a MITM solution to a MITM attack” :-) Just to keep the cat-n-mouse game exciting.

UPDATE: anchors added to image.

UPDATE2: what Mallory does is “ICMP DoS attack” (not to be confused with “ICMP flood”), once West Chamber can handle forged CM(control message), this MITM plan will be achievable.

继续阅读

“ For my friends and enemies. ” 已被炮击4次

  1. 我承认我在完全没有看完帖子只是瞄了一眼的情况下就无下限地推断这个是店长的崔莺莺萌化计划分析计划书了…

    Sword-Breaker的头像

    #1

    Sword-Breaker

    乘坐着 Google Chrome 4.1.249.1036 Google Chrome 4.1.249.1036 与 Windows 7 Windows 7

    发射于 01:58 on March 19th, 2010 [回复]

  2. 死磕完了前两段才看到LS的留言,豁然开朗中内牛满面了

    曙光再现的头像

    #2

    曙光再现

    乘坐着 Firefox 3.5.8 Firefox 3.5.8 与 Windows XP Windows XP

    发射于 08:32 on March 19th, 2010 [回复]

  3. 其实我是看到作者名字才点进来的~

    掌柜的马甲的头像

    #3

    掌柜的马甲

    乘坐着 Firefox 3.6 Firefox 3.6 与 Windows 7 Windows 7

    发射于 10:46 on March 19th, 2010 [回复]

  4. 张生真是个好人,连店长都写文了。

    az508的头像

    #4

    az508

    乘坐着 Internet Explorer 6.0 Internet Explorer 6.0 与 Windows XP Windows XP

    发射于 15:43 on March 22nd, 2010 [回复]


比特客栈的连珠合璧

比特客栈的东奔西走

比特客栈的旁门左道

News at: [2010/07/31 - 12:34] [2]

简单介绍:40岁的日本宅叔(目前是TRPG设计者兼同人作家)娶了20岁的中国姑娘,然后在网上发布生活漫画。内容取向见上图……

via 中国嫁日記 by 希有馬, h/t to popgo

News at: [2010/07/29 - 02:18] [4]

看来在我们打烊的日子里Pixiv更新了它的排名单格式,导致我们制作的Pixiv订阅源失效了。今晚抽空重新制作了一次,以下是各个订阅源的简介。

(继续阅读)…

News at: [2010/07/27 - 04:33] [12]

看完上面这张户松遥了吗?看完了吗?好,我们继续。

(继续阅读)…

News at: [2010/07/15 - 23:17] [8]

News at: [2010/07/14 - 22:25] [0]

If you tell the truth you don’t have to remember anything. – Mark Twain

这就是为什么中国的领导现在才想起来自己还在西太平洋大学读过博士。哦不对,是忘了澄清自己没在西太平洋大学读过博士。

News at: [2010/07/04 - 22:02] [4]

在人类成功环绕地球之前,航海的其中一个传说就是大洋尽头。新加坡海湾金沙酒店的空中花园的无限泳池,设计颇像World’s End的垂直瀑布。

image via flickr (1,2,3)

News at: [2010/07/03 - 18:01] [12]

Michael Sandel的哈佛课程Justice估计大家都有所听闻,课程中最常提及的便是所谓的效果论(Consequentialism)与其衍生的分支,功利主义(Utilitarianism)。而在最近加纳vs乌拉圭的进世界杯4强的比赛中,我们就看到了在这么一个极端的例子。

(继续阅读)…

News at: [2010/06/22 - 15:04] [14]

又要因为生活而移动,这次的目标是:魔都。离开山寨城之前找了个制高点截图,却发现忘带相机,于是渣画质。

再怎么PS,也不如在超市买水时照得这张经典。

啊对了,本文的重点其实是客栈因为搬家将进入更新低潮,每日访问的旅客可以稍事休息了,感谢你们的支持。(欢迎阅读客栈的老文章)