Hanz Ostmaster's revenge: An SSL Validation issue

Wingman

Level 4
Thread author
Verified
Well-known
Feb 6, 2017
154
687
268
Galaxy far away...
Why would I title a blog post with the name 'Hanz Ostmaster'? Don't worry, it's not some new named vulnerability, but it turns out this name has some significance. Do you see it? It requires a bit of imagination - consider a typical email policy: first letter of your first name, last name @ example.com. With our friend Mr. Ostmaster this will result in hostmaster@example.com. Does that seem like a problem to you? Turns out this email address can be a massive issue.
 
  • Like
Reactions: Wave