Jump to content

Comodo SSL compromised, fake certificates issued, updates rushed to WSUS, et al.


Recommended Posts

Posted (edited)

'Iranian' attackers forge Google's Gmail credentials - The Register

 

Extremely sophisticated hackers, possibly from the Iranian government or another state-sponsored actor, broke into the servers of a web authentication authority and counterfeited certificates for Google mail and six other sensitive addresses, the CEO of Comodo said.

 

Note: Comodo are a root certification authority that is trusted by default in all major browsers, so even if you don't use Comodo products yourself, your browser is vulnerable until updated.

 

Updates that block the fake certificates were quietly snuck into Firefox 4 just before the release, Chrome included the update in 10.0.648.151, and an update for IE has been rushed to Windows Update today, and is already in WSUS.

 

Certificates were issued for the following names:

 

  • login.live.com
  • mail.google.com
  • www.google.com
  • login.yahoo.com (3 certificates)
  • login.skype.com
  • addons.mozilla.org
  • "Global Trustee"

 

So, you know, nothing important or anything... :S

Edited by AngryTechnician
Updated to emphasise that you don't need to use Comodo products to be vulnerable
  • Thanks 1
Posted
Tip: If you set an install deadline in WSUS that is in the past (say today at midday), machines will install the update as soon as they check in with WSUS, instead of waiting for their regular daily update time (which they might have missed and therefore have to wait another 24 hours). The update does not appear to require a reboot.
  • Thanks 1
Posted
i dont use comodo products but i presume this is still an issue as they can fake certificates for different providers ie skype, gmail etc ??

Comodo are a root certification authority that is trusted by all major browsers. You don't need to be a customer of any of their products to be vulnerable. I've updated the top post to note this.

Posted
Cheers for the deadline tip, I've never really read into how the deadline thing works. I look forward to my WSUS server being hammered in the morning :p
Posted

ah remote access :p both a blessing and a curse. Great for getting stuff done.. Bad because you do stuff outside of work hours!

*goes back to service packing servers :(*

Posted

I wonder if the people responsible for this attack were also the ones behind the Stuxnet rootkit which used a stolen digital certificate from Realtek? :confused:

 

The digital certificate that belonging to Realtek Semiconductor that was used to sign a pair of drivers for the new Stuxnet rootkit has been revoked by VeriSign. The certificate was revoked Friday, several days after news broke about the existence of the new malware and the troubling existence of the signed drivers. (Source)
Posted

Another bump; plus if you use Safari you will want to read this article...

 

http://blog.intego.com/2011/03/24/protect-safari-from-fraudulent-digital-certificates/

 

The security breach threw a monkey wrench in this process, by allowing hackers to essentially pretend that a site of their own creation was in fact Google, Yahoo, or Skype. Backed by the fraudulent certificates, these fake sites could be used to trick people into giving up all sorts of personal information.

 

Luckily, certificate authorities can revoke those digital certificates, rendering them useless to the would-be hackers—but it only works if your browser knows the certificates have been revoked. This process doesn’t happen automatically in all browsers. Safari, in particular, relies on the built-in security management features of Mac OS X’s Keychain Manager—and Keychain Manager’s validation feature is off by default.

 

Fortunately, as Intego mentions in its blog post, it only takes a couple of clicks to make Safari safe from this potential vulnerability again. All you need to do is run Keychain Access (found in your /Applications/Utilities folder, or by just typing its name into Spotlight) and then make sure that the various certificate-revocation protocols are enabled in the app’s settings panel. Visit the link above for full instructions. However, it’s worth noting that enabling these options can slow down your browsing process. (Source)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...