Skip to content

GitLab

  • Menu
Projects Groups Snippets
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • C censorship-analysis
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 24
    • Issues 24
    • List
    • Boards
    • Service Desk
    • Milestones
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Monitor
    • Monitor
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Repository
  • Wiki
    • Wiki
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • The Tor Project
  • Anti-censorship
  • censorship-analysis
  • Issues
  • #40025

Closed
Open
Created Jan 11, 2022 by Nick Mathewson@nickm👉

Reported MITM on gitlab.torproject.org on Megafon in Russia

On tor-security, a user reports:

ISP Megafon uses the attached cert.

gitlab.torproject.org uses an invalid security certificate. The certificate is not trusted because it is self-signed. The certificate is only valid for 10.83.250.4 (Error code: sec_error_unknown_issuer)

certificate.crt

And then they reported:

GET / HTTP/1.1
Host: torproject.org
User-Agent:
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
DNT: 1
Connection: keep-alive

HTTP/1.1 302 Found
Location: http://m.megafonpro.ru/rkn?channel=2m

I don't know how useful this is, so I'm passing it on. I'm not sure how sensitive this is, so I'm marking it confidential. Feel free to make it public if you determine that there's nothing private in the cert. I can give you the user's email on request offline, if you want to reach out to them.

Cheers!

Edited Jan 11, 2022 by David Fifield
Assignee
Assign to
Time tracking