此存储库包含一些Go代码,用于演示最近发现的iOS和OS X中的SSL验证漏洞。
$ git clone https://github.com/gabrielg/CVE-2014-1266-poc.git
$ cd CVE-2014-1266-poc
$ go build main.go
$ ./main
# In another terminal
$ cd CVE-2014-1266-poc
$ go run http_server.go
然后,在受影响的机器上设置代理,指向运行代理服务器的机器的8080端口。HTTPS请求将被拦截并重定向到HTTP服务器,该服务器监听代理建立连接的UNIX域套接字。

在gironda.org上读点东西消磨时间。