<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>PKI | 今天abc看了啥🤔</title><description>现在我也不知道这频道发了啥了，各位慢慢吃瓜，将就着看联系我请去 @abc1763613206友链儿@cyberElaina@rvalue_daily@billchenla</description><link>https://channel.0w0.best</link><item><title>研究者发现自己可以注册一些 TLD 的旧 Whois 服务域名，并利用其获得 TLD 下非由自己控制域名的 TLS 证书</title><link>https://channel.0w0.best/posts/5555</link><guid isPermaLink="true">https://channel.0w0.best/posts/5555</guid><pubDate>Fri, 20 Sep 2024 02:55:54 GMT</pubDate><content:encoded>研究者发现自己可以注册一些 TLD 的旧 Whois 服务域名，并利用其获得 TLD 下非由自己控制域名的 TLS 证书。&lt;br /&gt;&lt;br /&gt;- watchTowr 的研究人员发现 .mobi 的旧 whois 服务域名过期，因而购买了此域名并在原有域名上架设了 whois 服务。&lt;br /&gt;- 研究人员发现 CA 服务 GlobalSign 允许使用 whois 记录中的邮箱作为验证邮箱，并且仍使用旧 whois 服务域名进行证书注册相关查证，因此可以为他们所用来申请任意 .mobi 域名的 TLS 证书。&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/&quot; target=&quot;_blank&quot;&gt;labs.watchtowr.com/~&lt;/a&gt;&lt;br /&gt;seealso: &lt;a href=&quot;https://news.ycombinator.com/item?id=41510252&quot; target=&quot;_blank&quot;&gt;HackerNews:41510252&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;/search/%23Whois&quot;&gt;#Whois&lt;/a&gt; &lt;a href=&quot;/search/%23MOBI&quot;&gt;#MOBI&lt;/a&gt; &lt;a href=&quot;/search/%23PKI&quot;&gt;#PKI&lt;/a&gt;&lt;a href=&quot;https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/&quot; target=&quot;_blank&quot;&gt;
  
  &lt;div&gt;watchTowr Labs&lt;/div&gt;
  &lt;img class=&quot;link_preview_image&quot; alt=&quot;We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI&quot; src=&quot;/static/https://cdn4.telesco.pe/file/pT3VwLDHEGNrNXrofirS_5dCQUOWamAFOL1lczOYuvk-MYLG8vLAVfiI-Auyg7oElhKm1LakvqgsgHxb3_J6qObEs5PWQzniazn6fa9v0J-Tywy1tjZTGwopBEFafNOwFQwYbdEJUv_XYpVMskHTTUzO7CNIEbQn1n7y98YRhmJ5yghp-uV-QC9Wc2V4QxelaNa2IObwUALODvjjfwZZ4884b2GC8JQIwOFMzlO_bObCnz_la6dy_1REOobfjahHqYI7uiXVb0oljrewFKPrOhV6Yqe8JQU91QXfl5YYcpSFYE6RfKvX072kZ4CzMvKRpDlpLz801cjCuXWxMZApCw.jpg&quot; loading=&quot;lazy&quot; /&gt;
  &lt;div&gt;We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI&lt;/div&gt;
  &lt;div&gt;Welcome back to another watchTowr Labs blog. Brace yourselves, this is one of our most astounding discoveries.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Summary&lt;br /&gt;&lt;br /&gt;What started out as a bit of fun between colleagues while avoiding the Vegas heat and $20 bottles of water in our Black Hat hotel rooms…&lt;/div&gt;
&lt;/a&gt;</content:encoded></item></channel></rss>