Microsoft warns: Fraudulent digital certificates issued for high-value

Borg 386

ADHD Senior Member
Guru
Gold Member
VIP
Local time
7:02 PM
Messages
5,489
Location
In a house with a cat trying to kill me
Microsoft today warned that Comodo has issued nine fraudulent digital certificates to a third party whose identity could not be sufficiently validated, a scenario that could allow attackers to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against all Web surfers.

According to the Microsoft advisory, the fraudulent Web certificates affect the Microsoft Live service, Google’s mail system, Yahoo and Skype log-ins.

  • login.live.com
  • mail.google.com
  • Google
  • login.yahoo.com (3 certificates)
  • login.skype.com
  • addons.mozilla.org
  • “Global Trustee”
The fact that valid HTTPS certificates for high-value web sites were issued to attackers is a worrying development (see essay from the Tor Project), especially since Comodo is a certification authority present in the Trusted Root Certification Authorities Store on all supported versions of Microsoft Windows.

Comodo has revoked these certificates, and they are listed in Comodo’s current Certificate Revocation List (CRL). In addition, browsers which have enabled the Online Certificate Status Protocol (OCSP) will interactively validate these certificates and block them from being used.

UPDATE: Attack originated in Iran
Comodo has published a blog post and an incident report with a claim that the attack originated from IP addresses in Iran.

“The attacker was well prepared and knew in advance what he was to try to achieve. He seemed to have a list of targets that he knew he wanted to obtain certificates for, was able quickly to generate the CSRs for these certificates and submit the orders to our system so that the certificates would be produced and made available to him,” Comodo said.
Read More:


Microsoft warns: Fraudulent digital certificates issued for high-value websites | ZDNet

EDIT: An update is available for all supported versions of Windows to help address this issue. For more information about this update, see Microsoft Knowledge Base Article 2524375.
 
Last edited:

My Computer My Computer

At a glance

Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1,...Intel Core 2 Duo 2.93GHzNot much with my ADHDATI Radeon HD 4350
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
Ouch, comodo seems to have really dropped the ball on that one.
 

My Computer My Computer

At a glance

Windows 7 x64Intel i7 2600kG.skill Ripjaw 16gigs @ 1866Nvidia gtx580 (evga)
Computer Manufacturer/Model Number
Insane hobo technologies. ;-)
OS
Windows 7 x64
CPU
Intel i7 2600k
Motherboard
Asrock z68 extreme 4 gen 3
Memory
G.skill Ripjaw 16gigs @ 1866
Graphics Card(s)
Nvidia gtx580 (evga)
Sound Card
Integrated HD audio + hdmi
Monitor(s) Displays
24" ASUS widescreen + 42" insignia
Screen Resolution
1080p (1920x1080)
Hard Drives
128 Samsung 830
256 Samsung 840
3 x 1tb storage drive (various)
1 western digital 1tb (eSATA)
1 Seagate 1tb (eSATA)
PSU
1 kilowatt SLI/Crossfire rated Silverstone modular
Case
NZXT Phantom + additional 220 fan
Cooling
Zalmann
Keyboard
Microsoft wireless 3000 (v2)
Mouse
MS - wireless 5000 (bluetrack)
Internet Speed
depends on if you ask me or my provider.
Other Info
The above information is provided as is, and the author assumes no responsibility for issues it may cause with your sanity or fanboyism.
Thank you for valuable information! ;)
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64 SP1AMD PHENOM II X6 1090T 3.2GHz8GB G.SKILL RIPJAWS - F3-10666CL7DSAPPHIRE ATI RADEON HD 5870 VAPOR X OC
Computer Manufacturer/Model Number
WALLONN7 / LIN BLACK SERIES II
OS
Windows 7 Ultimate x64 SP1
CPU
AMD PHENOM II X6 1090T 3.2GHz
Motherboard
GIGABYTE GA-890FXA-UD7
Memory
8GB G.SKILL RIPJAWS - F3-10666CL7D
Graphics Card(s)
SAPPHIRE ATI RADEON HD 5870 VAPOR X OC
Sound Card
REALTEK DOLBY HOME THEATER
Monitor(s) Displays
LED LG W2486L
Screen Resolution
1080p
Hard Drives
SEAGATE 1TB -ST31000528AS - AHCI MODE - AS SATA
PSU
ZALMAN ZM1000-HP 1000W
Case
THERMALTAKE XASER VI VG4000SWA
Cooling
140MM x3 / 120MM x1 AIR COOLING - THERMALTAKE
Keyboard
MICROSOFT DIGITAL MEDIA KEYBOARD 3000 - USB
Mouse
MICROSOFT BASIC OPTICAL MOUSE 2.0 - USB
Internet Speed
600KBPS
Other Info
MICROSOFT XBOX 360 CONTROLLER
I can honesty see this becoming more prevalent in the coming years.
 

My Computer My Computer

At a glance

Windows 7 x86/x64, Server 2008r2, Web Server ...i7 v2 3930K Steping stone 2G.SKILL Ripjaws Z Series 32GBAMD HD 5770
Computer Manufacturer/Model Number
SMN-Productions
OS
Windows 7 x86/x64, Server 2008r2, Web Server 2008
CPU
i7 v2 3930K Steping stone 2
Motherboard
ASUS Rampage IV Extreme
Memory
G.SKILL Ripjaws Z Series 32GB
Graphics Card(s)
AMD HD 5770
Monitor(s) Displays
Acer 21" and Samsung 20"
Hard Drives
Patriot Pyro 80GB
PSU
1000 Watt
Case
HAF-X
Cooling
4 Fans
Keyboard
Black Widow Ultimate
Incidents like this really dent my trust in these apparently respectable third party companies. I'll probably end up only being able to trust Microsoft and its security software when dealing with the Window's OS.
 

My Computer My Computer

At a glance

Windows 7 Professional 64 Bit SP1INTEL DUAL CORE 2.1Ghz4GB DDR3INTEL
Computer Manufacturer/Model Number
HP DV6 1330sa
OS
Windows 7 Professional 64 Bit SP1
CPU
INTEL DUAL CORE 2.1Ghz
Motherboard
N/A
Memory
4GB DDR3
Graphics Card(s)
INTEL
Sound Card
LAPTOP
Monitor(s) Displays
2
Screen Resolution
3200x1080
Hard Drives
250GB
PSU
LAPTOP
Case
LAPTOP
Cooling
LAPTOP
Keyboard
SOLID YEAR 260U
Mouse
USB
Internet Speed
20 MB/S
I lost my trust in comodo years ago, when I put it on three completely different systems and it immediately rendered all of them bsod making piles of garbage until I scrubbed it back off again.

It's quite possible MS will cut them off after this anyhow. It represents a serious problem for people using IE because of the way it handles sites presenting a proper certificate.
 

My Computer My Computer

At a glance

Windows 7 x64Intel i7 2600kG.skill Ripjaw 16gigs @ 1866Nvidia gtx580 (evga)
Computer Manufacturer/Model Number
Insane hobo technologies. ;-)
OS
Windows 7 x64
CPU
Intel i7 2600k
Motherboard
Asrock z68 extreme 4 gen 3
Memory
G.skill Ripjaw 16gigs @ 1866
Graphics Card(s)
Nvidia gtx580 (evga)
Sound Card
Integrated HD audio + hdmi
Monitor(s) Displays
24" ASUS widescreen + 42" insignia
Screen Resolution
1080p (1920x1080)
Hard Drives
128 Samsung 830
256 Samsung 840
3 x 1tb storage drive (various)
1 western digital 1tb (eSATA)
1 Seagate 1tb (eSATA)
PSU
1 kilowatt SLI/Crossfire rated Silverstone modular
Case
NZXT Phantom + additional 220 fan
Cooling
Zalmann
Keyboard
Microsoft wireless 3000 (v2)
Mouse
MS - wireless 5000 (bluetrack)
Internet Speed
depends on if you ask me or my provider.
Other Info
The above information is provided as is, and the author assumes no responsibility for issues it may cause with your sanity or fanboyism.
I didn't know about Comodo until I seen people recommending it here. Because of those recommendations I installed their firewall, but I found it to be over complicated in some areas and it was crashing some of the programs I use for work :o I restored a full system image to make sure that all of the HIPS hooks it probably installed into the kernel were gone.

In a way these developments are interesting, as Microsoft is being taken more serious in regards to security and protecting its end users. And it is all of those third party companies-- Sun with its Java, Adobe with its Flash/Reader and now Comodo being seen as the bad guys :)

I lost my trust in comodo years ago, when I put it on three completely different systems and it immediately rendered all of them bsod making piles of garbage until I scrubbed it back off again.

It's quite possible MS will cut them off after this anyhow. It represents a serious problem for people using IE because of the way it handles sites presenting a proper certificate.
 

My Computer My Computer

At a glance

Windows 7 Professional 64 Bit SP1INTEL DUAL CORE 2.1Ghz4GB DDR3INTEL
Computer Manufacturer/Model Number
HP DV6 1330sa
OS
Windows 7 Professional 64 Bit SP1
CPU
INTEL DUAL CORE 2.1Ghz
Motherboard
N/A
Memory
4GB DDR3
Graphics Card(s)
INTEL
Sound Card
LAPTOP
Monitor(s) Displays
2
Screen Resolution
3200x1080
Hard Drives
250GB
PSU
LAPTOP
Case
LAPTOP
Cooling
LAPTOP
Keyboard
SOLID YEAR 260U
Mouse
USB
Internet Speed
20 MB/S
Years ago on more than one forum I mentioned it was about time Microsoft got more serious about security because they had the money and personal to do the job. They were in the position to work with countries and industry to get the job done. I must say they have taken the ball and run with it. I think they are doing a upstanding job. Finding and repairing security problems. Helping shut down Botnets, torrents, ect.
 

My Computer My Computer

At a glance

Windows 10 Pro. 64/ version 1709 Windows 7 Pr...Intel i7-6800K @ 4.3Corsair Platinum 16 gig @2400EVGA GTX 1070 OC
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Years ago on more than one forum I mentioned it was about time Microsoft got more serious about security because they had the money and personal to do the job. They were in the position to work with countries and industry to get the job done. I must say they have taken the ball and run with it. I think they are doing a upstanding job. Finding and repairing security problems. Helping shut down Botnets, torrents, ect.

I agree with everything there but one item.

I don't think torrents are inherently bad, even though people use them for illegal purposes, they have their legitimate place as does all p2p. P2P represents a great method for sharing of free, open source, and creative commons materials.

The real problem is the people in charge of the torrent sites tend to not really care what they are hosting as long as they are making money off their ads and what not.

I'm not for demonizing the entire concept of p2p because of it though. People freaked out a long time ago over a similar device that allowed people access to information on a unheard of scale. It was called the printing press.
 

My Computer My Computer

At a glance

Windows 7 x64Intel i7 2600kG.skill Ripjaw 16gigs @ 1866Nvidia gtx580 (evga)
Computer Manufacturer/Model Number
Insane hobo technologies. ;-)
OS
Windows 7 x64
CPU
Intel i7 2600k
Motherboard
Asrock z68 extreme 4 gen 3
Memory
G.skill Ripjaw 16gigs @ 1866
Graphics Card(s)
Nvidia gtx580 (evga)
Sound Card
Integrated HD audio + hdmi
Monitor(s) Displays
24" ASUS widescreen + 42" insignia
Screen Resolution
1080p (1920x1080)
Hard Drives
128 Samsung 830
256 Samsung 840
3 x 1tb storage drive (various)
1 western digital 1tb (eSATA)
1 Seagate 1tb (eSATA)
PSU
1 kilowatt SLI/Crossfire rated Silverstone modular
Case
NZXT Phantom + additional 220 fan
Cooling
Zalmann
Keyboard
Microsoft wireless 3000 (v2)
Mouse
MS - wireless 5000 (bluetrack)
Internet Speed
depends on if you ask me or my provider.
Other Info
The above information is provided as is, and the author assumes no responsibility for issues it may cause with your sanity or fanboyism.
That's odd - WU said it was up to date - but didn't have that update.
 

My Computers My Computers

  • At a glance

    7 X64i5 84002x8gb 3200mhz
    Computer type
    PC/Desktop
    OS
    7 X64
    CPU
    i5 8400
    Motherboard
    gigabyte b365m ds3h
    Memory
    2x8gb 3200mhz
    Hard Drives
    various
    PSU
    pure power 11 400w cm
    Case
    Coolermaster
    Cooling
    cryorig m9i
  • At a glance

    7x64g54008gb ddr4 2400
    Computer type
    PC/Desktop
    OS
    7x64
    CPU
    g5400
    Motherboard
    ga b365m ds3h
    Memory
    8gb ddr4 2400
    PSU
    xfx pro 450w
That's odd - WU said it was up to date - but didn't have that update.

It was released the update (KB2524375) via Windows Update ... ;)
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64 SP1AMD PHENOM II X6 1090T 3.2GHz8GB G.SKILL RIPJAWS - F3-10666CL7DSAPPHIRE ATI RADEON HD 5870 VAPOR X OC
Computer Manufacturer/Model Number
WALLONN7 / LIN BLACK SERIES II
OS
Windows 7 Ultimate x64 SP1
CPU
AMD PHENOM II X6 1090T 3.2GHz
Motherboard
GIGABYTE GA-890FXA-UD7
Memory
8GB G.SKILL RIPJAWS - F3-10666CL7D
Graphics Card(s)
SAPPHIRE ATI RADEON HD 5870 VAPOR X OC
Sound Card
REALTEK DOLBY HOME THEATER
Monitor(s) Displays
LED LG W2486L
Screen Resolution
1080p
Hard Drives
SEAGATE 1TB -ST31000528AS - AHCI MODE - AS SATA
PSU
ZALMAN ZM1000-HP 1000W
Case
THERMALTAKE XASER VI VG4000SWA
Cooling
140MM x3 / 120MM x1 AIR COOLING - THERMALTAKE
Keyboard
MICROSOFT DIGITAL MEDIA KEYBOARD 3000 - USB
Mouse
MICROSOFT BASIC OPTICAL MOUSE 2.0 - USB
Internet Speed
600KBPS
Other Info
MICROSOFT XBOX 360 CONTROLLER
He sounds a lil too cocky. Ill say hes caught in two months.
 

My Computer My Computer

At a glance

Windows 7 x86/x64, Server 2008r2, Web Server ...i7 v2 3930K Steping stone 2G.SKILL Ripjaws Z Series 32GBAMD HD 5770
Computer Manufacturer/Model Number
SMN-Productions
OS
Windows 7 x86/x64, Server 2008r2, Web Server 2008
CPU
i7 v2 3930K Steping stone 2
Motherboard
ASUS Rampage IV Extreme
Memory
G.SKILL Ripjaws Z Series 32GB
Graphics Card(s)
AMD HD 5770
Monitor(s) Displays
Acer 21" and Samsung 20"
Hard Drives
Patriot Pyro 80GB
PSU
1000 Watt
Case
HAF-X
Cooling
4 Fans
Keyboard
Black Widow Ultimate
...
Two additional Registration Authorities, or RAs, that resell digital certificates for Comodo have been compromised, in addition to the original RA breached a week ago, Comodo said yesterday.

"Two further RA accounts have since been compromised and had RA privileges withdrawn," Robin Alden, chief technology officer at Jersey City, N.J.-based Comodo, wrote in a post on a Mozilla Developer security policy Google Groups thread. "No further mis-issued certificates have resulted from those compromises."
...
Comodo: Web attack broader than initially thought | InSecurity Complex - CNET News
 

My Computer My Computer

At a glance

Arch Linux 64-bit
OS
Arch Linux 64-bit
Comodo's first mistake was to outsource the selling of certificates to 3rd party companies whose security sucks. If Comodo had any sense they should do this in house where they can better protect their own systems. Or maybe Comodo's security also sucks.

Jim :geek:
 

My Computer My Computer

At a glance

Windows 8.1 Pro w/Media Center 64bit, Windows...Phenom II X6 1100TCrucial Balistic 8gb DDR3-1866 CL9MSI R6850 Cyclone IGD5 PE
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built
OS
Windows 8.1 Pro w/Media Center 64bit, Windows 7 HP 64bit
CPU
Phenom II X6 1100T
Motherboard
ASUS M5A99X EVO
Memory
Crucial Balistic 8gb DDR3-1866 CL9
Graphics Card(s)
MSI R6850 Cyclone IGD5 PE
Sound Card
On Board
Monitor(s) Displays
ASUS VE258Q 25" LED with DVI-HDMI-DisplayPort
Screen Resolution
1920 x 1080
Hard Drives
Two WD Cavier Black 2TB Sata III, WD My Book Essential 2TB USB 3.0
PSU
Seasonic X650 80 Plus GOLD Modular
Case
Corsair 400R
Cooling
Antec Kuhler H2O 620, Two 120mm and four 140mm
Keyboard
Logitech K120
Mouse
Logitech Marble Mouse USB, Logitech Precision Game Pad
Internet Speed
15MB
Antivirus
Norton IS 2013, Malwarebytes Pro Beta 2
Browser
IE-11, FF-27
Other Info
APC UPS ES 750, Netgear WNR3500L Gigabit & Wireless N Router with SamKnows Test Program, Motorola SB6120 Gigabit Cable Modem. Brother HL-2170W Laser Printer, Epson V300 Scanner
Back
Top