爱意满满的作品展示区。
ipconfiger

山寨 SSL

  •  
  •   ipconfiger · Mar 13, 2013 · 3153 views
    This topic created in 4884 days ago, the information mentioned may be changed or developed.
    https://gist.github.com/ipconfiger/5145056

    哈哈,山寨版SSL,HTML端Javascript用公钥加密密码,在Python端用私钥解密活得明文密码。这样在POST传输 的过程中就是加密了的密码了,公钥可以直接输出到HTML。
    5 replies    1970-01-01 08:00:00 +08:00
    dndx
        1
    dndx  
       Mar 13, 2013
    如何保证公钥在传输过程中没有被篡改?
    ipconfiger
        2
    ipconfiger  
    OP
       Mar 13, 2013
    @dndx 篡改了有啥用?公钥和私钥是配对滴,要么一对都篡改。加密传输是为了保证安全,篡改公钥最多达到破坏功能的目的,但是不会泄密的了。
    200
        3
    200  
       Mar 13, 2013
    我想1L的意思是没有有效的公钥验证机制,就无法杜绝中间人攻击。
    ipconfiger
        4
    ipconfiger  
    OP
       Mar 13, 2013
    @200 嗯,这么说的话有道理,不过山寨的嘛,浏览器的SSL本身也只能提醒你不安全而已
    ipconfiger
        5
    ipconfiger  
    OP
       Mar 13, 2013
    @200 btw,如果http输出被篡改的话,验证公钥也不顶用,他根本可以绕开加密而直接在html代码中注入脚本来直接从键盘事件里获取密码,so,差不多就好啦。
    About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Solana   ·   4919 Online   Highest 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 26ms · UTC 05:40 · PVG 13:40 · LAX 22:40 · JFK 01:40
    ♥ Do have faith in what you're doing.