Microsoft Said: Stolen SSL Certificates May Be Dangerous While Updating Your Windows


Microsoft said Sunday that a digital certificate stolen from a Dutch company could not be used to force-feed customers malware through its Windows Update service. The company's assertion came after a massive theft of more than 500 SSL (secure socket layer) certificates, including several that could be used to impersonate Microsoft's update services, was revealed by Dutch authorities and several other affected developers.

"Attackers are not able to leverage a fraudulent Windows Update certificate to install malware via the Windows Update servers,"
said Jonathan Ness, an engineer with the Microsoft Security Response Center (MSRC), in a Sunday blog post. "The Windows Update client will only install binary payloads signed by the actual Microsoft root certificate, which is issued and secured by Microsoft."

Seven of the 531 certificates now known to have been fraudulently obtained by hackers in July were for the domains update.microsoft.com and windowsupdate.com, while another six were for *.microsoft.com. According to Microsoft, the certificates issued for windowsupdate.com couldn't be used by attackers because the company no longer uses that domain. (Windows Update is now at windowsupdate.microsoft.com..) However, those for update.microsoft.com -- the domain for Microsoft Update -- and the wildcard *.microsoft.com could be.

As Ness said, updates delivered via Microsoft's services are signed with a separate certificate that's closely held by the company. Without that code-signing certificate, attempts to deliver malware disguised as an update to a Windows PC would fail. Other vendors, including Apple, also sign software updates with a separate certificate. The certificates for the various Microsoft domains were issued by DigiNotar, a Dutch company that last week admitted its network had been hacked in mid-July. The company initially believed it had revoked all the fraudulent certificates, but later realized it had overlooked one that could be used to impersonate any Google service, including Gmail. DigiNotar went public only after users reported their findings to Google.
Criminals or governments could use the stolen certificates to conduct "man-in-the-middle" attacks, tricking users into thinking they were at a legitimate site when in fact their communications were being secretly intercepted. Microsoft has added its voice to the chorus from rival browser makers, notably Google and Mozilla, about the seriousness of the situation. Like its competitors, Microsoft will also permanently block all DigiNotar certificates.

"We are in the process of moving all DigiNotar owned or managed [certificate authorities] to the Untrusted Root Store, which will deny access to any website using DigiNotar certificates," said Dave Forstrom, a director in the Microsoft Trustworthy Computing group, in an emailed statement Sunday.

Forstrom did not set a date by when Microsoft would block all DigiNotar certificates, including those used by the Dutch government, which has been a major customer of the company. Google updated Chrome on Saturday to block all DigiNotar certificates, while Mozilla plans to do the same on Tuesday for Firefox.

However, Microsoft's partial ban of DigiNotar certificates -- which it instituted last week -- and the complete sanction now in the works only protects users running Windows Vista, Windows 7, Windows Server 2008 and Windows Server 2008 R2. Customers still on Windows XP or Windows Server 2003 must wait for an update specific to those operating systems; Ness said only that that update would "be available soon."
Until that Windows XP update is available, users can protect themselves by manually deleting the DigiNotar root from the list of approved certificate-issuing authorities. 

For more information and to look at the Microsoft press release click Here 

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

4d0r4b13 Said: Famous Music Director Vishal and Shekhar's Official Blog is Vulnerable


Bollywood famous singer and music director Vishal and Shekhar's official blog is vulnerable to non persistent XSS. Indian hacker 4ng31 4k4 4d0r4b13 found this vulnerability. 

Vulnerable Site:-
http://pentagram.in/

Vulnerable Link:-
http://pentagram.in/?s=%3Cscript%3Ealert%28%22found+by+4ng31+4k4+4d0r4b13%22%29%3C%2Fscript%3E


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Dutch Government is Investigating The Iranian Cyber Attack

The Dutch government is investigating whether Iran may have been involved in hacking Dutch state websites after digital certificates were stolen. Vincent van Steen, Dutch interior ministry spokesman, declined to say whether Iranian authorities in the Netherlands or Iran had been contacted, and said more details would be published in a letter to the Dutch parliament early next week.
But Mr van Steen confirmed the veracity of a report by the Dutch news agency ANP saying the cabinet was looking into whether the Iranian government played a part in breaking into Dutch government websites.
Such websites may no longer be safe after the digital theft of internet security certificates from Dutch IT company DigiNotar, the interior ministry said in a statement. Officials at the Iranian embassy in The Hague were not immediately available for comment nor was there an immediate reply to emails asking for comment. Google said in its security blog on Aug. 29 that it had received reports of attacks on Google users, that "the people affected were primarily located in Iran", and that the attacker used a fraudulent certificate issued by DigiNotar.

-News Source (Telegraph, Register)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Turkish Hacker Group (Turkguvenligi) Strikes, Now the Victim is The Register, Vodafone, Acer, UPS & National Geographic Channel


Turkguvenligi the unknown Turkish hacker group strikes the WWW with a bang. This time the target was some high profile websites like famous media The Register also lots of high profile companies like VodafoneAcer, UPS & National Geographic Channel. According to the first step of investigation the mthod of hacking was some thing like this, Turkguvenligi managed to hack into the DNS panel of the reg­is­trar and mod­ify the con­fig­u­ra­tion of arbi­trary sites, to use their own DNS (ns1?.yumur?tak?abugu?.com and ns2?.yumur?tak?abugu?.com) and redi­rect those web­sites to their defaced page. But still the motive of this manage is not clear though the hacker group send a Message:- 

“Turkgu­ven­Ligi” and “4 Sept. We TurkGu­ven­ligi declare this day as World Hack­ers Day – Have fun ;) h4ck y0u” .

Previously Turkguvenligi hacked the job portal of FBI.

To see all the archived mirror of this hacker team click Here


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Government of Prince Edward Island Hacked (16480+ Users Personal Information Exposed By THE ION)


The Official Website of the Government of Prince Edward Island, Canada is vulnerable is SQL-i and the entire Database hacked by “THE ION” of TEAM OPEN FIRE AND TEAM BLACK LIST. More than 16480 users personal information such as name, address, family data,CREDIT CARD NUMBERS compromised, The entire city’s people around 16400 personal certificates such as date of birth, family registrations were also exposed publicly.

To see the exposed Credentials Click Here

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

SQL & XSS Vulnerability Found on Facebook Application




Zero strikes again and again the victim is Facebook. This time he found SQL-i and also XSS vulnerability on 2 Facebook applications.

2 infected applications are:-

1. Ebook
2. ireadit 

SQL-i vulnerability on Ebook Application


Link:-
http://apps.facebook.com/ebokapp/


XSS Vulnerability on ireadit Application

Link:-
http://apps.facebook.com/ireadit/

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

85+ Websites Hacked By ZCompany Hacking Crew - [ZHC]


More than 85 websites Hacked and defaced by Zhc Disastar of well known hackers group ZCompany Hacking Crew (ZHC) to spread message. 

List of Hacked Sites & Mirrors:-
http://pastebin.com/bESiyDVc


Message of ZHC:-

"...Free Kashmir .. Freedom is our goal..// End the Occupation. . . .

This institutionalized impunity with which the killings of civilians by military and police forces in Jammu and Kashmir continues should be a source of shame for India which propagates to be a democracy!

Kashmir does not want militarized governance - STOP killing children, raping women and imprisoning the men! They just want freedom! Freedom from the evil of the Indian Military!

You will never kill the Kashmiri spirit and remember one thing India; Ghandi himself said - Freedom is never dear at any price. It is the breath of life. What would a man not pay for living?

Everyday 100s of innocent people are abused, raped and even killed in kashmir by the indian army, a third of the deaths are children, - we dont want war, take back your men, your tanks and your guns and go back to where you came from, all we ask is for freedom, you can kill us but you cant kill us all, we shall not give up, giving up is not an option.

who are the real soldiers? the children holding stones or the Army men holding guns? ..."

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...