Feeds

MS patches bogus certificate hole on NT, XP

The rest of you, Mac users too, will have to wait

  • alert
  • submit to reddit

3 Big data security analytics techniques

Microsoft has finally begun patching a severe security flaw in its implementation of digital-certificate basic-constraints checking which we've been ranting about for nearly a month. The stuff-up makes it possible for SSL and e-mail signature certs to be forged.

Currently, Win-NT and XP users have fixes available for their kit. This leaves Win-98, 98-SE, ME, and 2K users waiting for patches which will be 'issued shortly,' the company says. There will also be patches for numerous versions of Internet Explorer, MS-Office, and Outlook Express for the Mac. On Windows it's necessary only to fix CryptoAPI for each OS version, but on Macs the situation is reversed; each Microsoft application needs to be fixed separately -- so if you're using more than one, you'll need more than one patch.

Interestingly, MS rates this Trustworthy Computing stuff-up 'Critical', in contradiction to their earlier whitewash of the issue.

Even now, with the 'C' word plastered all over the MS bulletin, the company can't resist plugging in every bit of soft-pedal boilerplate from its original 'what, us worry?' PR offering. There is no mention of the fact that a valid certificate and key have already been circulated with SSLsniff, an exploit tool developed by Mike Benham, who first reported the issue.

There is also no mention of the way SSLsniff can be used to intercept a third party's SSL session where the victim and attacker are on the same LAN. Indeed, there's no mention of Benham himself, but that's probably due to Redmond's irritation with him for spilling the beans before they were ready to have them spilt. Of course there was always a simple workaround: Windows users could have used Mozilla for both e-mail and browsing, and simply not been troubled. For its part, MS seems not to have appreciated the the elegance of this solution.

The MS bulletin and links to the patches can be found here. ®

SANS - Survey on application security programs

More from The Register

next story
Android engineer: We DIDN'T copy Apple OR follow Samsung's orders
Veep testifies for Samsung during Apple patent trial
This time it's 'Personal': new Office 365 sub covers just two devices
Redmond also brings Office into Google's back yard
Batten down the hatches, Ubuntu 14.04 LTS due in TWO DAYS
Admins dab straining server brows in advance of Trusty Tahr's long-term support landing
Microsoft lobs pre-release Windows Phone 8.1 at devs who dare
App makers can load it before anyone else, but if they do they're stuck with it
Half of Twitter's 'active users' are SILENT STALKERS
Nearly 50% have NEVER tweeted a word
Windows XP still has 27 per cent market share on its deathbed
Windows 7 making some gains on XP Death Day
Internet-of-stuff startup dumps NoSQL for ... SQL?
NoSQL taste great at first but lacks proper nutrients, says startup cloud whiz
Windows 8.1, which you probably haven't upgraded to yet, ALREADY OBSOLETE
Pre-Update versions of new Windows version will no longer support patches
Microsoft TIER SMEAR changes app prices whether devs ask or not
Some go up, some go down, Redmond goes silent
Red Hat to ship RHEL 7 release candidate with a taste of container tech
Grab 'near-final' version of next Enterprise Linux next week
prev story

Whitepapers

Designing a defence for mobile apps
In this whitepaper learn the various considerations for defending mobile applications; from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.