<div> 
<!-- WP QUADS Content Ad Plugin v. 2.0.92 -->
<div class="quads-location quads-ad2526 " id="quads-ad2526" style="float:none;margin:0px 3px 3px 3px;padding:0px 0px 0px 0px;" data-lazydelay="0">

</div>
 <h2>Locked out of accessing my firewall</h2><p>After I changed my Antivirus software I used to access a remote firewall publicly on the internet. This firewall has a local selfsigned certificate that no web browser trusts.</p><div> 
<!-- WP QUADS Content Ad Plugin v. 2.0.92 -->
<div class="quads-location quads-ad2522 " id="quads-ad2522" style="float:none;margin:0px 3px 3px 3px;padding:0px 0px 0px 0px;" data-lazydelay="0">

</div>
 </div><div> 
<!-- WP QUADS Content Ad Plugin v. 2.0.92 -->
<div class="quads-location quads-ad2530 " id="quads-ad2530" style="float:none;margin:0px 3px 3px 3px;padding:0px 0px 0px 0px;" data-lazydelay="0">

</div>
 </div><div> 
<!-- WP QUADS Content Ad Plugin v. 2.0.92 -->
<div class="quads-location quads-ad2525 " id="quads-ad2525" style="float:none;margin:0px 3px 3px 3px;padding:0px 0px 0px 0px;" data-lazydelay="0">

</div>
 </div><p>Although I added the root certificate to my root store but still none of the browsers would allow me to access it and result in the below error:</p><blockquote><p>Your connection is not private<br>
Attackers might be trying to steal your information from myapp.domain.com (for example, passwords, messages, or credit cards). Learn more<br>
NET::ERR_CERT_INVALID<br>
myapp.domain.com normally uses encryption to protect your information. When Brave tried to connect to myapp.domain.com this time, the website sent back unusual and incorrect credentials. This may happen when an attacker is trying to pretend to be myapp.domain.com, or a Wi-Fi sign-in screen has interrupted the connection. Your information is still secure because Brave stopped the connection before any data was exchanged.</p>
<p>You cannot visit myapp.domain.com right now because the website sent scrambled credentials that Brave cannot process. Network errors and attacks are usually temporary, so this page will probably work later.</p></blockquote><h2>On Chrome</h2><p><a href="https://www.moh10ly.com/wp-content/uploads/2020/06/image-13.png"><img style="margin: 0px; display: inline; background-image: none;" title="image" src="https://www.moh10ly.com/wp-content/uploads/2020/06/image_thumb-13.png" alt="image" width="785" height="691" border="0"></a> 
</p><div> 
<!-- WP QUADS Content Ad Plugin v. 2.0.92 -->
<div class="quads-location quads-ad2527 " id="quads-ad2527" style="float:none;margin:0px 3px 3px 3px;padding:0px 0px 0px 0px;" data-lazydelay="0">

</div>
 </div><h2>On Firefox</h2><p><a href="https://www.moh10ly.com/wp-content/uploads/2020/06/image-14.png"><img style="display: inline; background-image: none;" title="image" src="https://www.moh10ly.com/wp-content/uploads/2020/06/image_thumb-14.png" alt="image" width="1028" height="423" border="0"></a></p><p>I searched the web for many work arounds but none of them almost worked including this one which says you can use &ldquo;Thisisunsafe&rdquo; or &ldquo;badidea&rdquo; on chrome but it did not work.</p><p><a href="https://medium.com/@dblazeski/chrome-bypass-net-err-cert-invalid-for-development-daefae43eb12">https://medium.com/@dblazeski/chrome-bypass-net-err-cert-invalid-for-development-daefae43eb12</a></p><h2>Using Fiddler</h2><p>Since I use fiddler to sniff packets and troubleshoot issues on my computer, I remembered that Fiddler has the feature of decrypting traffic (MITM). Fiddler inserts its own root certs and force the traffic to go through it first which makes all the websites trusted even in the case of this error ::ERR_CERT_INVALID</p><h2>Solution:</h2><p>So to make this work even temporarily so you can access whatever page you lost access to. All you have to do is:</p><ul>
<li>Install Fiddler</li>
<li>Let Fiddler Decrypt traffic: To do this go to Tools>; Options >; HTTPS and select &ldquo;Capture HTTPS Connects and Decrypt Traffic&rdquo;</li>
<li>Accept and import the root certificates.</li>
<li>Click Ok</li>
<li>Start Capturing traffic by clicking on the left corner icon <a href="https://www.moh10ly.com/wp-content/uploads/2020/06/image-15.png"><img style="margin: 0px; display: inline; background-image: none;" title="image" src="https://www.moh10ly.com/wp-content/uploads/2020/06/image_thumb-15.png" alt="image" width="206" height="67" border="0"></a></li>
</ul><p><a href="https://www.moh10ly.com/wp-content/uploads/2020/06/image-16.png"><img style="display: inline; background-image: none;" title="image" src="https://www.moh10ly.com/wp-content/uploads/2020/06/image_thumb-16.png" alt="image" width="544" height="367" border="0"></a></p><ul>
<li>Now try to browse the page you couldn&rsquo;t access previously and you&rsquo;ll get a prompt to accept its certificate. Click Yes if you&rsquo;re sure of the page and continue.</li>
</ul><p><a href="https://www.moh10ly.com/wp-content/uploads/2020/06/image-17.png"><img style="display: inline; background-image: none;" title="image" src="https://www.moh10ly.com/wp-content/uploads/2020/06/image_thumb-17.png" alt="image" width="975" height="653" border="0"></a></p><p>Here we go, I got back access to my Pfsense but notice you&rsquo;ll only be able to access the URL if the capturing is on.</p><p>The moment you turn Capturing off the page will not be accessible again.</p><div> 
<!-- WP QUADS Content Ad Plugin v. 2.0.92 -->
<div class="quads-location quads-ad2529 " id="quads-ad2529" style="float:none;margin:0px 3px 3px 3px;padding:0px 0px 0px 0px;" data-lazydelay="0">

</div>
 </div><p><a href="https://www.moh10ly.com/wp-content/uploads/2020/06/clip_image001-1.png"><img style="margin: 0px; display: inline; background-image: none;" title="clip_image001" src="https://www.moh10ly.com/wp-content/uploads/2020/06/clip_image001_thumb-1.png" alt="clip_image001" width="1028" height="565" border="0"></a></p></div>

<!-- WP QUADS Content Ad Plugin v. 2.0.92 -->
<div class="quads-location quads-ad2523 " id="quads-ad2523" style="float:none;margin:0px 3px 3px 3px;padding:0px 0px 0px 0px;" data-lazydelay="0">

</div>


Reset and manage your Active Directory users' Passwords Active Directory is one of the most…
Finding Exchange Database hidden mailboxes. Story:Maybe you have been in this situation before, trying to…
If you're using a Proxy server in your firewall or in your network and have…
Story:I got some clients that have reported some of their users being locked out and…
Delegate Permissions This is a code that I have wrote recently to check if an…
Story: I got a request from a client who constantly gets CVs and have to…