[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FD] Charter Spectrum Business HTTP MITM


You probably don't need to be told otherwise, but do not trust Charter
(or any ISP) with your HTTP traffic even if you're paying for a business
connection and expect internet without tampering or analysis. I recently
started receiving redirects to a Terms & Conditions page on IPv4 HTTP
traffic. My tests indicate they don't do it with IPv6 through their 6rd
Border Relay and of course they can't do it with HTTPS. Surprisingly
most of my traffic avoids IPv4 HTTP so I am not sure how long this has
been going on.

They insert RST packets and then redirect you to a page to present you
new T&C they want you to accept. The URL looks like this:


I've attached a packet dump of this in action.

Stay safe

Attachment: charter.pcapng
Description: Binary data

Sent through the Full Disclosure mailing list
Web Archives & RSS: http://seclists.org/fulldisclosure/