Results 1 to 4 of 4
Like Tree1Likes
  • 1 Post By solin

Thread: Microsoft Confirms!

  1. #1
    Experienced User
    Overall activity: 0%

    Join Date
    Sep 2010
    Posts
    848
    Liked
    201 times
    Points
    21,839

    Microsoft Confirms!

    Microsoft Confirms Spoofed Certificates for Microsoft.com and Windowsupdate.com from DigiNotar

    Spoofed certificates for .microsoft.com and .windowsupdate.com are among those issued by Dutch-based DigiNotar, which has been at the center of a scandal involved fraudulent certificates used to attack users of Google.com sites.

    Microsoft has confirmed officially that certificates for its own online properties from DigiNotar have also been compromised, and already took measures in order to ensure that customers running Internet Explorer on Windows Vista and Windows 7 are protected.
    Dave Forstrom, director, Trustworthy Computing reveals that while the investigation into the matter continues, a couple of DigiNotar root certificates have been removed.

    “As always, we continue to take action to ensure the safety of our customers. We have already removed the two DigiNotar root certificates, which encompass what we believe to be the vast majority of the fraudulently issued digital certificates, from the Certificate Trust List. All fraudulent certificates that have been disclosed to Microsoft roll up to one of those two root certificates,” Forstrom said.

    Vista and Windows 7 users which also run IE have been protected against attacks since the end of August.

    “Users of Vista and later operating systems have been protected since we released Security Advisory 2607712 on August 29,” Forstrom added.

    “In addition, customers using Windows Update on any platform are not at risk of exploitation from the windowsupdate.com certificate, since that domain is no longer in use. The Windows Update service uses multiple means of checking that the content distributed is legitimate and uncompromised.”


    Cybercriminals can potentially leverage the fraudulent certificates in order to spoof legitimate websites, and pass them for genuine online properties.

    Since the fraudulent root certificates have been removed, IE will flag fake sites using them, and inform users that they’re about to be victims of an attack.

    “We are also working to update Security Advisory 2607712 for customers on XP and Server 2003 and will continue to investigate any additional issues arising from the spoofed *.microsoft.com certificate. We will provide updated information to customers as it becomes available,” Forstrom promised.
    Source

  2. #2
    Moderator
    Overall activity: 100.0%

    Join Date
    May 2010
    Location
    Eire /The Garden of Ireland
    Posts
    5,486
    Liked
    1749 times
    Points
    31,018
    Thank you for the information Solin, first i heard of Microsoft mentioned, i wonder if part of it was an inside job to make money as you have to wonder how a site like this gets hacked and the response time been so slow, if it wasn't so high profile i could understand the delay..

    Nice work Solin

  3. #3
    I'd rather be fishing!
    Overall activity: 0%

    Join Date
    Jan 2011
    Location
    Minnesota, USA
    Posts
    3,155
    Liked
    1543 times
    Points
    4,220
    Thanks for sharing this news solin! Its good to know about this.
    Life isn't about waiting for the storm to pass, it's about learning to dance in the rain!

  4. #4
    Malware Hunter
    Overall activity: 0%

    Join Date
    Sep 2009
    Location
    Kolkata, India
    Posts
    485
    Liked
    104 times
    Points
    6,801
    Nice share solin. Keep up the good work.

 

 

Similar Threads

  1. Microsoft C++
    By TeXaCo in forum General Forum
    Replies: 2
    Last Post: 09-06-2011, 08:42 PM
  2. Google Confirms It Aims to Own Your Online ID
    By Stranger in forum General Forum
    Replies: 10
    Last Post: 09-04-2011, 03:28 PM
  3. Microsoft Office 365
    By princeaniket in forum General Forum
    Replies: 10
    Last Post: 10-23-2010, 05:53 AM
  4. Google vs Microsoft.
    By kavinraja in forum Chat
    Replies: 67
    Last Post: 03-26-2010, 05:33 PM
  5. Mozilla confirms infected Firefox add-ons
    By noaccount in forum General Forum
    Replies: 15
    Last Post: 02-07-2010, 08:21 AM
All times are GMT +8. The time now is 12:52 AM.