HN user

nibbler

5 karma
Posts0
Comments3
View on HN
No posts found.

MITM has nothing to do with TLS. It just means that the attacker is talking to both sides simultaniously, giving them the impression to be talking to each other directly. Thus the attacker is able to read manipulate the traffic. This can be used to hand out the attackers own certificates, but is in no way limited to it. I'd call this attack as the library is doing it MITM.

to quote from [0,p67], which is the dissertation of the guy writing it:

The HeartbeatResponse must contain the same payload as the request it answers, which allows the requesting peer to verify it. This is necessary to distinguish expected responses from delayed ones of previous requests, which can occur because of the unreliable transport.

[0] http://duepublico.uni-duisburg-essen.de/servlets/DerivateSer...