Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 4th, 2010, 11:07 PM
tgell tgell is offline
Frequent Poster
 
Join Date: Nov 2004
Posts: 793
Default Certificate Snatching—ZeuS Copies Kaspersky’s Digital Signature

Quote:
While conducting continuous threat-monitoring activities, Trend Micro threat researchers identified multiple suspicious files that included a strange digital signature. This signature immediately caught our attention, as it seemed to be signed by legitimate antivirus company Kaspersky.

Article
  #2  
Old August 5th, 2010, 01:13 AM
chronomatic chronomatic is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,324
Default Re: Certificate Snatching—ZeuS Copies Kaspersky’s Digital Signature

Lesson: Check hashes on these certs

A related story posted a while back is in this thread. There I break down a lot of reasons why I think this latest fear mongering over rogue peeps jacking certs is vastly overstated and overall is nothing to worry about if basic precautions (i.e., checking hashes) are taken.
  #3  
Old August 5th, 2010, 10:23 AM
funkydude's Avatar
funkydude funkydude is offline
Massive Poster
 
Join Date: Apr 2004
Posts: 5,997
Default Re: Certificate Snatching—ZeuS Copies Kaspersky’s Digital Signature

I'd wouldn't really call this an issue, the screenshots themselves show that the certificates are infact invalid.

I'd be far more concerned over malware like stuxnet that managed to get Realtek's actual key and signed their malware with a valid certificate, Microsoft had to invalidate that certificate from Verisign.
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #4  
Old August 5th, 2010, 10:55 AM
chronomatic chronomatic is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,324
Default Re: Certificate Snatching—ZeuS Copies Kaspersky’s Digital Signature

Quote:
Originally Posted by funkydude
I'd wouldn't really call this an issue, the screenshots themselves show that the certificates are infact invalid.

I'd be far more concerned over malware like stuxnet that managed to get Realtek's actual key and signed their malware with a valid certificate, Microsoft had to invalidate that certificate from Verisign.

Realtek peeps are idiots then. They should never store their master key in a place where malware can touch it. Furthermore, the malware would have to have some way of cracking the key's passphrase (unless the private key had no passphrase, which is total idiocy).

Let me add, that this non-story the OP posted is nothing but a way for Trend Micro to attempt to make Kaspersky look bad (even though Kaspersky did nothing wrong whatsoever and this "issue" is indeed a non-issue). The hashes don't match. I mean that's what hashes are for. Everything is working as it's supposed to work! This is actually a very retarded story. "Full retard" at that.
  #5  
Old August 5th, 2010, 11:33 AM
CogitoTesting CogitoTesting is offline
Frequent Poster
 
Join Date: Jul 2009
Location: Sea of Tranquility
Posts: 896
Default Re: Certificate Snatching—ZeuS Copies Kaspersky’s Digital Signature

There is a thread already for that subject. Please continue the conversation there instead.

http://www.wilderssecurity.com/showthread.php?t=278822


Thanks.
__________________
Genuine Machine : On Access and On Demand Security Apparatus: Maya, My Dearest Beloved
Fake Machine (Windows 7): Private Firewall 7, Avast Antivirus 7 (free), and BufferZone 4
  #6  
Old August 5th, 2010, 03:45 PM
funkydude's Avatar
funkydude funkydude is offline
Massive Poster
 
Join Date: Apr 2004
Posts: 5,997
Default Re: Certificate Snatching—ZeuS Copies Kaspersky’s Digital Signature

Quote:
Originally Posted by chronomatic
Let me add, that this non-story the OP posted is nothing but a way for Trend Micro to attempt to make Kaspersky look bad (even though Kaspersky did nothing wrong whatsoever and this "issue" is indeed a non-issue). The hashes don't match. I mean that's what hashes are for. Everything is working as it's supposed to work! This is actually a very retarded story. "Full retard" at that.

I agree.

Quote:
Originally Posted by chronomatic
Realtek peeps are idiots then. They should never store their master key in a place where malware can touch it. Furthermore, the malware would have to have some way of cracking the key's passphrase (unless the private key had no passphrase, which is total idiocy).

Well it's not confirmed how they got Realtek's key but some people believe blackmail/goverments were involved. I believe they got a key from another Taiwanese company also.
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:10 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums