sigv linux 信号,用kalinux 下面的mitmproxy 工具查看请求的时候会发现请求一个symcd.com...

文章探讨了在使用Mozilla Firefox时发现的对gv.symcd.com的请求,了解到这与在线证书状态协议(OCSP)有关,用于检查数字证书的撤销状态。该请求由Symantec Corporation拥有,创建于2013年,涉及多个子域名,所有这些都指向同一个IP地址。博客还列出了多个symcd.com的子域名,强调了它们可能在证书验证过程中的角色。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

一、用kalinux 下面的mitmproxy 工具查看请求的时候发现一个问题

请求下面会有一个请求ss.symcd.com 这个到底是干什么用的呢???

Morning! Hope you are having a great weekend. I’ve been experimenting with some network monitoring of HTTP requests and responses in Mozilla Firefox. While playing around with one of the tools I’m evaluating I noticed a request to gv.symcd.com:

eb48d8a8ab34ee81e54bb6dfb958fd4f.png

I had not heard of the symcd.com domain before so I got curious. The request is a “application/ocsp-request“. OCSP is a abbreviation for Online Certificate Status Protocol and it is an Internet protocol used for retrieve the revocation status of a digital certificate.

That’s what the symcd.com connection is about: Checking the revocation state for some  certificate. The tool I used to track the network traffic does not have any advanced features to decode the OSCP communication so I don’t know exactly what information Firefox requests from symcd.com.

So, who owns symcd.com? The WHOIS database answer is Symantec Corporation:

Registrant Organization: Symantec Corporation

Registrant Street: 350 Ellis Street

Registrant City: Mountain View

Registrant State/Province: CA

Registrant Postal Code: 94043

Registrant Country: US

Symcd.com was created on 2013-12-12.

I did not find much information about gv.symdc.com, and the reason for that is probably because there’s a large number of subdomains used. I found this list over at VirusTotal:

sm.symcd.com

gz.symcd.com

gp.symcd.com

tl.symcd.com

sn.symcd.com

tm.symcd.com

gq.symcd.com

sk.symcd.com

gw.symcd.com

si.symcd.com

gx.symcd.com

gk.symcd.com

s.symcd.com

sw.symcd.com

gu.symcd.com

sh.symcd.com

tf.symcd.com

t.symcd.com

tn.symcd.com

gv.symcd.com

ta.symcd.com

gd.symcd.com

st.symcd.com

tg.symcd.com

sr.symcd.com

sd.symcd.com

sf.symcd.com

sg.symcd.com

th.symcd.com

ga.symcd.com

gn.symcd.com

se.symcd.com

sv.symcd.com

tj.symcd.com

su.symcd.com

tb.symcd.com

ti.symcd.com

tc.symcd.com

sc.symcd.com

gm.symcd.com

sb.symcd.com

gb.symcd.com

ss.symcd.com

sj.symcd.com

gj.symcd.com

td.symcd.com

sa.symcd.com

tk.symcd.com

I checked a few of the domains, and they all resolved to the 23.43.139.27 IP address.

Thanks for reading!

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值