Fun VPN tricks due to Apple owning all of 17.X.X.X
好的,我现在需要帮用户总结一下这篇文章的内容,控制在100个字以内。首先,我得仔细阅读文章,理解主要信息。 文章讲的是作者在2018年夏天作为苹果安全工程师实习生的经历。他在飞往奥斯汀的航班上发现了一个有趣的事情。飞机上提供付费Wi-Fi和免费短信服务,他选择了免费的短信。然后他连接了苹果的VPN,结果发现所有应用程序都能连接,甚至可以在Chrome上浏览网页,虽然速度很慢。 原来苹果拥有17.0.0.0/8的IP地址空间,所有的公共服务、服务器和域名都使用这个范围内的IP。航空公司为了允许iMessage通信,将所有17.X.X.X的流量都放行了。而苹果的VPN也使用了这个IP段,所以也被放行了。作者利用这个发现,在整个夏天免费使用JetBlue的Wi-Fi。 现在我要把这些信息浓缩到100字以内。要抓住关键点:作者的身份、时间、地点、发现的过程以及结果。同时要确保语言简洁明了。 可能的结构是:作者作为苹果实习生,在2018年夏天发现通过VPN利用航空公司对特定IP放行的漏洞,从而免费使用飞机Wi-Fi。 检查一下是否超过了字数限制,并确保没有遗漏重要信息。 </think> 作者在2018年夏天作为苹果安全工程师实习生时,在航班上发现通过苹果VPN利用航空公司对特定IP地址放行的方式免费使用Wi-Fi。 2021-3-12 16:3:51 Author: blog.jonlu.ca(查看原文) 阅读量:0 收藏

I worked as a security engineer intern at Apple during the Summer of 2018, on the Threat Intelligence team.

Apple

I remember one day I was flying from Cupertino to Austin to meet with my manager, who was based out of Texas. I made a bit of a fun discovery on the plane, due to the way that Apple's VPN was set up.

On the flight, they had options to pay for the full flights wifi for $20, or you could get free messaging. I didn't really need to do any browsing so I opted for the messaging.

I connected my VPN and all my applications started connecting, and I could browse in Chrome (albeit slowly). I was surprised since this should just be for iMessage traffic.

Apple owns all of the 17.0.0.0/8 IP space. All of its public facing services, servers, and domains are behind some 17.X.X.X IP address.

It seemed like the airline was just whitelisting any traffic to 17.X.X.X, as they knew that that would be where the iMessage servers would be. Since Apple's VPN was also behind a 17 dot IP address, it got whitelisted traffic as well.

I used this for the remainder of the summer, as a free way of getting Wi-Fi on jetblue.


文章来源: https://blog.jonlu.ca/posts/apple-wifi
如有侵权请联系:admin#unsafe.sh