Phony SSL certificates - update your system

Closed Thread
Thread Tools
  #1  
Old 03-24-2011, 07:47 AM
ajbrown's Avatar
ajbrown ajbrown is offline
Sage
Join Date: Oct 2009
Location: Mallory Square (9 months/year), TBD the rest
Posts: 2,641
Thanks: 12
Thanked 20 Times in 11 Posts
Default Phony SSL certificates - update your system

I read this today over coffee and figured I would share with TOTV. No need to panic, but worth making sure your system is updated. In summary someone was able to create 9 phony SSL certificates, some for domain names we know like google, yahoo, etc. You need to update your CRL (certificate revocation list). Microsoft has released an update (KB2524375). I am looking if this automatically takes care of Firefox or Chrome or if they need to be updated separately.

Here is the info at Microsoft:
http://www.microsoft.com/technet/sec...y/2524375.mspx
http://support.microsoft.com/kb/2524375
From the article:


SSL Certificates are the Internet equivalent of drivers' licenses, said Paul Turner, the vice president of products and customer solutions at Venafi, an Enterprise Key and Certificate Management firm. The bogus certificates could be used in phishing or man in the middle attacks against organizations that haven't updated their certificate revocation lists, he said. They could also be used to sign applications and plug ins, he said
.

Full article here:
http://threatpost.com/en_us/blogs/ph...-others-032311

Last edited by ajbrown; 03-24-2011 at 08:06 AM. Reason: Added microsoft update info
  #2  
Old 03-24-2011, 01:51 PM
K9-Lovers's Avatar
K9-Lovers K9-Lovers is offline
Soaring Eagle member
Join Date: Jan 2010
Location: Village of El Cortez. Before: Canada, NY, VA, AL, AK, NV, DE & France, Germany
Posts: 2,135
Thanks: 0
Thanked 0 Times in 0 Posts
Default

Thank you! My computer alerted me this morning to a new update, which I downloaded. So I just checked the number and it is the fix you mention: KB2524375.

Thank you for alerting us.
__________________
K9-Lovers
  #3  
Old 03-25-2011, 09:48 AM
JohnXI JohnXI is offline
Junior Member
Join Date: Jul 2010
Location: Near Toronto, Ontario, Canada and OBG in the Villages
Posts: 22
Thanks: 0
Thanked 0 Times in 0 Posts
Default

Or if you have a router and are vaguely technically cognisant you could just use OpenDNS, free. Info from http://www.opendns.com/solutions/overview/ Solves phishing among other lurgies. Enjoy.
Closed Thread


You are viewing a new design of the TOTV site. Click here to revert to the old version.

All times are GMT -5. The time now is 02:29 PM.