Showing posts with label Certificate Trust List. Show all posts
Showing posts with label Certificate Trust List. Show all posts

Thursday, 19 March 2015

Finn Gets Microsoft SSL Certificate By Sending Email


The reason that Microsoft this week an SSL certificate for Windows Live invalidated came as a Finnish system had requested via email and received. It was revoked certificate for the domain Live.fi issued and made ​​it possible to carry out phishing and man-in-the-middle attacks. Opposite the Finnish Tivi let the guy know now how he got hold of the certificate.

When Microsoft domain Live.fi launched it was possible to register several aliases that are normally used for administrative matters. The Finnish system decided in his own words "a joke" the alias hostmaster@live.fi to create its own email address, which to his surprise, also failed. Through this alias he could then try to apply for the certificate for the domain. SSL certificates are issued by Certificate Authorities. In the case of the wrongly issued certificate for Live.fi was issued by the Certificate Authority Comodo.

Before an SSL certificate for a domain can be registered, the requesting party must prove that he or she is the owner of the domain. For this show Comodo send a confirmation email to an email address like admin @, admin @, postmaster @, hostmaster @ or webmaster @ domain for which the certificate is requested.

The Finnish system decided by the alias hostmaster@live.fi the certificate for the domain Live.fi to ask and indeed received the confirmation email in his inbox. The man, the Finnish telecoms watchdog warned the problem below, but got no help. Then he warned Microsoft, but even there it remained silent until Microsoft this week decided to withdraw the wrongly issued certificate.

Wednesday, 18 March 2015

Microsoft Warns Of Rogue SSL Certificate


Microsoft has warned Internet for a wrongly issued SSL certificate for the domain " Live.fi "that could be used to perform phishing attacks, spoof content and Man-in-the-middle attacks on Windows Live users. Live .fi is a Finnish domain where users can log in with a Microsoft account. Through the wrongly issued certificate, an attacker could create a malicious website, which browsers should show that it is a valid website. Also, an attacker who is between the user and the Internet may be intercepted by the certificate credentials and other data.

Microsoft says that it is not aware of attacks. Meanwhile, the certificate has been revoked by the Certificate Authority (CA) that issued the certificate. According to Paul van Brouwershaven GlobalSign involves Comodo, that would be misled by a false email account to create the certificate and issue.

Measures

To protect users against fraudulent use of the certificate will Microsoft on all supported Windows versions, the Certificate Trust List (CTL) update. In the case of Windows 8 and 8.1, Windows RT and RT 8.1, Windows Server 2012 and 2012 R2 and for devices running Windows Phone 8 and 8.1 users do not do anything, since these versions of Windows are automatically protected.

For Windows Vista, Windows 7, Windows Server 2008 and 2008 R2 users also need to take any action, as the automatic updater of revoked certificates is enabled. In the case of Windows Server 2003 or for users who do not use the automatic updater of revoked certificates, Microsoft recommends that every now available update ( 2.9175 million to install) directly.