Attacks/Breaches
3/30/2011
01:30 PM
50%
50%

Comodo Reports Two More Registration Authorities Hacked

The digital certificate issuer has deactivated the affected accounts and begun to implement security and validation reforms.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
Two new registration authority (RA) accounts have been compromised at Comodo, the digital certificate issuer revealed Tuesday.

"Two further RA accounts have since been compromised and had RA privileges withdrawn. No further mis-issued certificates have resulted from those compromises," said Robin Alden, chief technical officer of Comodo, in a Usenet post. He said that no private Comodo keys were accessed or stolen.

The compromised accounts, which have been deactivated, were discovered during an investigation into a recent incident in which an attacker -- self-identified as being a solo Iranian hacker -- was able to fraudulently issue five certificates for domains including Firefox add-ons, Gmail, and Microsoft Live.

How were the two new RAs -- not named by Comodo -- compromised? According to Alden, most RAs must confirm all digital certificate requests by sending an email to a person with an email address on the requesting domain, or to a person that's explicitly mentioned as a contact in a site's WHOIS entry.

But 9% of the RAs that work with Comodo weren't using that process. In the case of the recent incident, that was because "the RA did a -- verified by Comodo -- good job of validating domain control and had a good and close relationship with his small number of customers," said Alden. "Also he spoke the same language as his customers."

The threat that Comodo was mitigating, he said, was that an RA might not be paying enough attention to validation. "What we had not done was adequately consider[ed] the new -- to us -- threat model of the RA being the subject of a targeted attack and entirely compromised."

Comodo said it's taking steps to prevent RAs -- even when their websites are completely compromised by attackers -- from being able to issue fraudulent certificates. For starters, Comodo implemented IP address restriction and two-factor authentication for all RAs. The latter should be live within two weeks, when all RAs have received their hardware tokens. "Until that process is complete Comodo will review 100% of all RA validation work before issuing any certificate," said Alden.

In addition, Comodo will stop issuing certificates to RAs from the root maintained by Mozilla. Because the certificates were subordinate to the root, Mozilla couldn't easily deactivate them when warned that they were fraudulent. Instead, Mozilla had to hard-code a fix into Firefox.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5395
Published: 2014-11-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R007B100D03SP01C03, E5180s-22 before 21.270.21.00.00, and E586Bs-2 before 21.322.10.00.889 allow remote attackers to hijack the authentication of users ...

CVE-2014-7137
Published: 2014-11-21
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM before 3.6.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) contactid parameter in an addcontact action, (2) ligne parameter in a swapstatut action, or (3) project_ref parameter to projet/tasks/contact.php; (4...

CVE-2014-7871
Published: 2014-11-21
SQL injection vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev36 and 7.6.x before 7.6.0-rev23 allows remote authenticated users to execute arbitrary SQL commands via a crafted jslob API call.

CVE-2014-8090
Published: 2014-11-21
The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nes...

CVE-2014-8469
Published: 2014-11-21
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web script or HTML via the User-Agent header.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?