Clarify what's happening in intro docs

This commit is contained in:
Tarjei Husøy 2016-06-03 23:53:18 -07:00
parent 4bad8cf825
commit 8ec2e9de4e

View file

@ -2,24 +2,22 @@ from __future__ import print_function
# This script demonstrates how to setup a Man-in-the-Middle (MitM) attack on a # This script demonstrates how to setup a Man-in-the-Middle (MitM) attack on a
# Postgres connection with SSLMODE=require or less. Attack is mitigated by # Postgres connection with SSLMODE=require or less. Attack is mitigated by
# setting SSLMODE=verify or SSLMODE=verify-full, which requires you to get the # setting SSLMODE=verify-ca or SSLMODE=verify-full, which requires you to get
# certificate of either your server or a CA that has signed it's certificate. # the certificate of either your server or a CA that has signed it's
# certificate.
# What the script does: # What the script does:
# listen on socket for ssl startup messages # * Bind to 5432 and listen for incoming connections
# reply with 'S' (supported?) # * If someone connects over plaintext, request password to be sent in the clear
# Do TLS handshake with random cert/key # * If someone requests to connect over SSL, initiate the SSL connection with a
# Tell client to authenticate over plaintext to capture the password # self-signed certificate, then ask for password in plaintext
# Initiate database connection to actual backend using the supplied password # * Initiate TLS connection to actual database with the supplied credentials
# Proxy all traffic between the client and the actual database # * Proxy all traffic between the client and the actual database
# The backend database to proxy must be given as an argument on the command # The target database must be given as an argument on the command line.
# line for now, but in an actual attack you would read this from the redirect
# fields on the IP packets or similar, depending on how you're performing the
# attack.
# PS: Please don't look to this script for examples of how to write good socket # PS: Please don't look to this script for examples of how to write good socket
# code, this is just a quick proof of concept. # code, this is just a proof of concept.
import argparse import argparse
import hashlib import hashlib