Linux Today: Linux News On Internet Time.
Search Linux Today
search.internet.com
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Become a Marketplace Partner

internet.commerce
Be a Commerce Partner














The Linux Channel at internet.com
Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Subscribe News
Subscribe PR
Subscribe Security

internet.com
IT
Developer
Internet News
Small Business
Personal Technology

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

 






Current Newswire:

Amahi Linux Home Server 4.2

Matthias Ettrich Receives German Federal Cross of Merit

Using Windows Is Like...

Installing Ubuntu 9.10

Hands-on: OpenMoko WikiReader is simple, appealing

Perl far from dead, more popular than you think

Microsoft Exchange alternatives

Kubuntu 9.10: A Mixed Bag

Could Microsoft switch to Linux?

Red Hat Virtualization Manager for Windows Only?




Systems Implementation Engineer II – Disk-Based Back-Up/Replication/RedHat Linux (PA)
Next Step Systems
US-PA-Philadelphia

Justtechjobs.com Post A Job | Post A Resume
:CERT Advisory: Unauthentic "Microsoft Corporation" Certificates
CERT Advisory: Unauthentic "Microsoft Corporation" Certificates
Mar 23, 2001, 14 :11 UTC (13 Talkback[s]) (4851 reads)

CERT Advisory CA-2001-04 Unauthentic "Microsoft Corporation" Certificates

   Original release date: March 22, 2001
   Last revised: March 22, 2001
   Source: CERT/CC

   A complete revision history can be found at the end of this file.

Systems Affected

   Systems whose users run code signed by Microsoft Corporation.

Overview

   On January 29 and 30, 2001, VeriSign, Inc. issued two certificates to
   an individual fraudulently claiming to be an employee of Microsoft
   Corporation. Any code signed by these certificates will appear to be
   legitimately signed by Microsoft when, in fact, it is not. Although
   users who try to run code signed with these certificates will
   generally be presented with a warning dialog, there will not be any
   obvious reason to believe that the certificate is not authentic.

I. Description

   Microsoft released a security bulletin on March 22, 2001, describing
   two certificates issued by VeriSign to an individual fraudulently
   claiming to be an employee of Microsoft. The full text of Microsoft's
   security bulletin is available from their web site at

       http://www.microsoft.com/technet/security/bulletin/MS01-017.asp

   Additional information about this issue is also available from
   VeriSign's web site:

       http://www.verisign.com/developer/notice/authenticode/index.html

   This issue presents a security risk because even a reasonably cautious
   user could be deceived into trusting the bogus certificates, since
   they appear to be from Microsoft. Once accepted, these certificates
   may allow an attacker to execute malicious code on the user's system.

   This problem is the result of a failure by the certificate authority
   to correctly authenticate the recipient of a certificate. Verisign has
   taken the appropriate action by revoking the certificates in question.
   However, this in itself is insufficient to prevent the malicious use
   of these certificates until a patch has been installed, because
   Internet Explorer does not check for such revocations automatically.

II. Impact

   Anyone with the private portions of the certificates can sign code
   such that it appears to have originated from Microsoft Corporation. If
   the user approves the execution of code signed by one of the bogus
   certificates, it can take any action on the system with the privileges
   of the user who approved the execution. The fake certificates can only
   be used for Authenticode signing.

III. Solution

Check "Microsoft Corporation" Certificates

   You can identify the fake certificates by checking the validity dates
   and serial numbers of the certificates. When prompted to authorize the
   execution of code signed by "Microsoft Corporation", press the "More
   Info" button to obtain additional information about the certificate
   used to sign the code.

   The fake certificates have the following description:

          Issued to: Microsoft Corporation
          Issued by: VeriSign Commercial Software Publishers CA
          Valid from 1/29/2001 to 1/30/2002
          Serial number is 1B51 90F7 3724 399C 9254 CD42 4637 996A

          Issued to: Microsoft Corporation
          Issued by: VeriSign Commercial Software Publishers CA
          Valid from 1/30/2001 to 1/31/2002
          Serial number is 750E 40FF 97F0 47ED F556 C708 4EB1 ABFD

   No legitimate certificates were issued to Microsoft between January 29
   and 30, 2001. Certificates with these initial validity dates or serial
   numbers should not be authorized to execute code.

   The certificate revocation list for the fake certificates can be found
   at

          http://crl.verisign.com/Class3SoftwarePublishers.crl

Apply a Patch from Your Vendor

   While there do not appear to be any patches available at this time
   that directly address this issue, Microsoft is working on producing
   patches that will ensure the invalid certificates are not used.

Appendix A. - Vendor Information

Microsoft Corporation

   Microsoft has published a security bulletin describing this issue at

          http://www.microsoft.com/technet/security/bulletin/MS01-017.asp

Netscape

   Netscape takes all security and privacy issues very seriously. The
   Netscape browser does not allow the execution of ActiveX controls,
   signed or unsigned, and therefore Netscape users are not vulnerable to
   exploits which rely on signed ActiveX. In the unlikely event that
   Netscape users are presented with signed content from Microsoft
   requesting enhanced privileges, Netscape users can protect themselves
   by denying permission to any such request.
   ______________________________________________________________________

   This document is available from:
   http://www.cert.org/advisories/CA-2001-04.html
   ______________________________________________________________________

CERT/CC Contact Information

   Email: cert@cert.org
          Phone: +1 412-268-7090 (24-hour hotline)
          Fax: +1 412-268-6989
          Postal address:
          CERT Coordination Center
          Software Engineering Institute
          Carnegie Mellon University
          Pittsburgh PA 15213-3890
          U.S.A.

   CERT personnel answer the hotline 08:00-20:00 EST(GMT-5) / EDT(GMT-4)
   Monday through Friday; they are on call for emergencies during other
   hours, on U.S. holidays, and on weekends.

Using encryption

   We strongly urge you to encrypt sensitive information sent by email.
   Our public PGP key is available from

   http://www.cert.org/CERT_PGP.key

   If you prefer to use DES, please call the CERT hotline for more
   information.

Getting security information

   CERT publications and other security information are available from
   our web site

   http://www.cert.org/

   To subscribe to the CERT mailing list for advisories and bulletins,
   send email to majordomo@cert.org. Please include in the body of your
   message

   subscribe cert-advisory

   * "CERT" and "CERT Coordination Center" are registered in the U.S.
   Patent and Trademark Office.
   ______________________________________________________________________

   NO WARRANTY
   Any material furnished by Carnegie Mellon University and the Software
   Engineering Institute is furnished on an "as is" basis. Carnegie
   Mellon University makes no warranties of any kind, either expressed or
   implied as to any matter including, but not limited to, warranty of
   fitness for a particular purpose or merchantability, exclusivity or
   results obtained from use of the material. Carnegie Mellon University
   does not make any warranty of any kind with respect to freedom from
   patent, trademark, or copyright infringement.
     _________________________________________________________________

   Conditions for use, disclaimers, and sponsorship information

   Copyright 2001 Carnegie Mellon University.

   Revision History
March 22, 2001: Initial release

Related Stories:
MSNBC: Microsoft certificate bug crashes Netscape browser(Jan 17, 2000)


Index Mode   |   Flat Mode   |   Thread Mode   |   Thread Flat  
  Talkback(s) Name  and Date
1. insert linux cd int cd-rom	
2. reboo ...   ultimate solution   
george
Mar 23, 2001, 14:33:56
 
This episode has been forewarned for a l ...   Digital signatures: not ready   
John Doe
Mar 23, 2001, 14:52:38
 
I never trust code from Microsoft in the ...   How is this a problem?   
Rajendra
Mar 23, 2001, 14:54:49
 
> I never trust code from Microsoft in t ...   Re: How is this a problem?   
Don Brock
Mar 23, 2001, 15:31:23
 
> This episode has been forewarned for a ...   Re: Digital signatures: not ready   
Gene Scott
Mar 23, 2001, 15:48:09
 
> It's the broken model of not using ...   Re: Re: Digital signatures: not ready   
Anonymous
Mar 23, 2001, 16:53:20
 
This is why the new plan for BIND to use ...   Certificates and BIND   
bleezer
Mar 23, 2001, 17:03:58
 
Look it up.

There is no such thing as ...   Attack Trees, by Bruce Schneier   
Brandioch Conner
Mar 23, 2001, 17:13:33
 
This story from CNET:


> Commentary: ...   And on the same day...   
ac
Mar 23, 2001, 18:14:46
 
> Then why do you use hotmail?

I don& ...   Re: Re: How is this a problem?   
Rajendra
Mar 23, 2001, 22:01:20
 
> But then, I guess the other side of th ...   Re: Re: Re: Digital signatures: not ready   
Gene Scott
Mar 24, 2001, 08:50:33
 
> This is why the new plan for BIND to u ...   Re: Certificates and BIND   
Rainer Weikusat
Mar 24, 2001, 10:34:49
 
> This isn't even a moving target.
 ...   Re: Attack Trees, by Bruce Schneier   
Rainer Weikusat
Mar 24, 2001, 10:36:02
 
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!






..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP

internet.commediabistro.comJusttechjobs.comGraphics.com

Search:

WebMediaBrands Corporate Info

Legal Notices, Licensing, Reprints, Permissions, Privacy Policy.
Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs