PDA

View Full Version : New hack on Comodo reseller exposes private data. And then there were four


Mr.PC
May 25th, 2011, 05:51 AM
New hack on Comodo reseller exposes private data. And then there were four. (http://www.theregister.co.uk/2011/05/24/comodo_reseller_hacked/)

funkydude
May 25th, 2011, 05:56 AM
Here I was wondering why it's been a while since our last bit of Comodo drama. ::) Quality humour.

clayieee
May 25th, 2011, 07:25 AM
darn it, the last certification issue didnt teach a lesson to comodo, they didnt make their security stronger

Mr.PC
May 25th, 2011, 07:31 AM
-{ Quote: "darn it, the last certification issue didnt teach a lesson to comodo,
they didnt make their security stronger" }-
Yeap, they didn't. :(

clayieee
May 25th, 2011, 07:40 AM
thats why i dont feel safe using their products, there's always a doubt about them

Pedro
May 25th, 2011, 08:14 AM
So the resellers don't use Defense+?

clayieee
May 25th, 2011, 09:24 AM
no its not about the antivirus, its about the issuing certificates.

funkydude
May 25th, 2011, 09:28 AM
-{ Quote: "no its not about the antivirus, its about the issuing certificates." }-

I think he was being sarcastic in hinting that the resellers don't use D+ to protect their servers.

clayieee
May 25th, 2011, 09:32 AM
i doubt if they use Comodo Enterprise.

funkydude
May 25th, 2011, 09:34 AM
-{ Quote: "i doubt if they use Comodo Enterprise." }-

Lol, yes, that's the point...

clayieee
May 25th, 2011, 09:39 AM
I'll never trust comodo if this happened again.

Cudni
May 25th, 2011, 10:57 AM
OT posts removed

Matthijs5nl
May 25th, 2011, 11:36 AM
Everytime there is serious news about Comodo (e.g. on trustworthy newssites, no dodgy messages by Melih or whatever he is called) it enforces my opinion that I never ever want to use any Comodo product since the company is not trustworthy.

clayieee
May 25th, 2011, 11:38 AM
so do i

littlebits
May 25th, 2011, 04:03 PM
Is this an example of how Comodo is "Creating Trust Online"? :o

If so then I want out.;D

Thanks.:D

J_L
May 25th, 2011, 11:30 PM
They need to improve their firewall, and other server protection. I wonder if they're using their client products on servers.

harsha_mic
May 26th, 2011, 02:56 PM
As per the mod, comodo resellers are not owned/manged by comodo. Thats just an another company which sells comodo certificates.

source (post - 3): hxxp://forums.comodo.com/general-discussion-off-topic-anything-and-everything/is-comodo-under-attack-t73015.0.html;msg519803#new

Thanks,
Harsha.

littlebits
May 26th, 2011, 03:51 PM
-{ Quote: "As per the mod, comodo resellers are not owned/manged by comodo. Thats just an another company which sells comodo certificates.

source (post - 3): hxxp://forums.comodo.com/general-discussion-off-topic-anything-and-everything/is-comodo-under-attack-t73015.0.html;msg519803#new

Thanks,
Harsha." }-

So Comodo is trying to say that this website (http://www.comodobr.com/) is not a part of them? Yet it has the Comodo logo plain as day.

I smell a rat.;D

harsha_mic
May 27th, 2011, 01:17 AM
Nope. Volunteers(mods) are saying that...

clayieee
May 27th, 2011, 01:20 AM
lets see what steps they will do, will they improve or remain hackable

Warlockz
May 29th, 2011, 02:59 PM
-{ Quote: "Comodo president and CEO, Melih Abdulhayoglu, said Comodo systems were never compromised. He also said no certificates were issued as a result of the breach, and that the reseller had no access to Comodo databases.

“So as a summary: its an SQL attack (fairly common) on a company in Brazil who sells some of our products.” he wrote in an email. “Nothing to report really.”" }-

OMG a Resellers Web Server Got hacked.....and? who cares it has nothing to do with Comodo....so unless you were an employee at the resellers in Brazil you have nothing to worry about....Period!

~ Off Topic Comment Removed ~ Download BackTrack (http://www.backtrack-linux.org/) and you can test out your own Web Server security setup you think is impenetrable, that is if you have a Web Server?

-{ Quote: "
So Comodo is trying to say that this website is not a part of them? Yet it has the Comodo logo plain as day.

I smell a rat." }-
What is a Reseller? Your answer is in the quote below...Originally Posted at Comodo Forums (http://forums.comodo.com/general-discussion-off-topic-anything-and-everything/is-comodo-under-attack-t73015.0.html;msg519803#new).
-{ Quote: "
A reseller in this instance is one who is selling certificates.

Think of it like this:

You purchase a copy of finance software at a local office store, when you take the software home install it on your computer and register the software with your personal information on the software company's website.

The office store you bought the software at, has its website hacked, however that doesn't mean the information you used to register the software with the software maker is compromised, they are two separate companies.

It's the same thing here, people purchase the certificates from this company, just because the company was hacked doesn't mean that any information pertaining to your Comodo certificate was leaked as that information is stored on Comodo servers, not this reseller's server.

By "division" Ewen means it is not part of Comodo, it is a separate company not owned or operated by Comodo in any way.

By "instance" Ewen means that in this scenario there is no sensitive data leak like there could have been if an actual Comodo server was compromised.

Remember this was just a company which sells some of Comodo products, they are not owned, operated, or in any way managed by Comodo, and as such they do not have any sensitive data pertaining to Comodo customers in their servers." }-
-{ Quote: "
keep in mind the hack was on a web server, which is not like a client operating system at all, many webservers use linux in some form or another as well.
" }-
-{ Quote: "As per the mod, comodo resellers are not owned/manged by comodo. Thats just an another company which sells comodo certificates.

source (post - 3): hxxp://forums.comodo.com/general-discussion-off-topic-anything-and-everything/is-comodo-under-attack-t73015.0.html;msg519803#new

Thanks,
Harsha." }-

you dont have to use hxxp here, Wilders does'nt care if you post a hot link (http://forums.comodo.com/general-discussion-off-topic-anything-and-everything/is-comodo-under-attack-t73015.0.html;msg519803#new) to Comodo Forums (http://forums.comodo.com/general-discussion-off-topic-anything-and-everything/is-comodo-under-attack-t73015.0.html;msg519803#new) dude

Spooony
June 24th, 2011, 12:25 AM
Last time they got cracked by the Iranian Government. Was after the Stuxnet saga. Maybe they were looking to sign some windows files for a counter worm like Jmicron and Realtek ones did.

Hungry Man
June 24th, 2011, 03:56 AM
lmao you guys serious? Comodo Reseller.

Who gives a **** about some random company that's only affiliation with Comodo is that they purchased their products? This has nothing to do with Comodo as a company.

Noob
June 24th, 2011, 02:28 PM
I would go with the D00ds saying these are just resellers ::)

cm1971
June 25th, 2011, 04:10 AM
-{ Quote: "I would go with the D00ds saying these are just resellers ::)" }-
Yes there has been enough drama with their CEO that you don't have to manufacture stuff like this that isn't there. ;D