Read More:Microsoft today warned that Comodo has issued nine fraudulent digital certificates to a third party whose identity could not be sufficiently validated, a scenario that could allow attackers to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against all Web surfers.
According to the Microsoft advisory, the fraudulent Web certificates affect the Microsoft Live service, Google’s mail system, Yahoo and Skype log-ins.
The fact that valid HTTPS certificates for high-value web sites were issued to attackers is a worrying development (see essay from the Tor Project), especially since Comodo is a certification authority present in the Trusted Root Certification Authorities Store on all supported versions of Microsoft Windows.
- login.live.com
- mail.google.com
- login.yahoo.com (3 certificates)
- login.skype.com
- addons.mozilla.org
- “Global Trustee”
Comodo has revoked these certificates, and they are listed in Comodo’s current Certificate Revocation List (CRL). In addition, browsers which have enabled the Online Certificate Status Protocol (OCSP) will interactively validate these certificates and block them from being used.
UPDATE: Attack originated in Iran
Comodo has published a blog post and an incident report with a claim that the attack originated from IP addresses in Iran.
“The attacker was well prepared and knew in advance what he was to try to achieve. He seemed to have a list of targets that he knew he wanted to obtain certificates for, was able quickly to generate the CSRs for these certificates and submit the orders to our system so that the certificates would be produced and made available to him,” Comodo said.
Microsoft warns: Fraudulent digital certificates issued for high-value websites | ZDNet
EDIT: An update is available for all supported versions of Windows to help address this issue. For more information about this update, see Microsoft Knowledge Base Article 2524375.
Last edited:
My Computer
At a glance
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1,...Intel Core 2 Duo 2.93GHzNot much with my ADHDATI Radeon HD 4350
- Computer type
- PC/Desktop
- Computer Manufacturer/Model Number
- Dell Hell oh Well
- OS
- Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
- CPU
- Intel Core 2 Duo 2.93GHz
- Memory
- Not much with my ADHD
- Graphics Card(s)
- ATI Radeon HD 4350
- Monitor(s) Displays
- 24" HDTV/Monitor
- Screen Resolution
- Blurry after a Scotch or 2
- Hard Drives
- 1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
- Case
- Don't get on my case...man :D
- Cooling
- I have an Air Conditioner & Diet Pepsi
- Keyboard
- Saitek Cyborg
- Mouse
- 10 yr old MS optical mouse that still works
- Internet Speed
- Never fast enough
- Antivirus
- Various
- Browser
- Various

I restored a full system image to make sure that all of the HIPS hooks it probably installed into the kernel were gone.