No-no, this is not stealing the target's existing certs; this is generating new ones, probably from a different CA. Combined with the ability to redirect the target's traffic, it offers a way to do MITM on an SSL connection.
Of course, if the target is actually reading their logs, they may notice that suddenly all of their requests are coming from the same IP number. ;-)
Re: Insufficient
Date: 2008-08-29 06:28 pm (UTC)Of course, if the target is actually reading their logs, they may notice that suddenly all of their requests are coming from the same IP number. ;-)