Monday, June 6, 2016

What would you do if your web browser was built as a MITM?

I've been working on a project, and somebody said to me "Is there a way of this working without javascript, because javascript doesn't work on opera mini"

This led me to investigate how opera mini handles javascript.

Well, it handles EVERYTHING as a man-in-the-middle attack. Every URL, image, file passes through an opera "proxy" that is designed to render the webpage (including javascript) in a datacentre, and then pass to the browser in binary code.

Every time I clicked a button that would perform a javascript action, the page reloaded. So yes, it is useless for javascript, but what about normal browsing?

What if your tablet uses opera mini, and you do some online banking? Your passwords ARE NOT safe, as they transit opera's proxy servers - but not only that, OPERA SHOWS YOU YOUR BANK'S SSL CERT!! OPERA IS LITERALLY BEING A MAN IN THE MIDDLE, AND INTERCEPTING (AND OPENING) SSL PACKETS!!!

Proof: http://ift.tt/1zkvobO



Submitted June 06, 2016 at 09:55PM by Teh_Nameless_One http://ift.tt/1XxxaXJ via TikTokTikk

No comments:

Post a Comment